CVE-2019-19343: High severity redhat jboss-remoting vulnerability
A flaw was found in Undertow as shipped in Jboss EAP before version 7.2.4. A memory leak in HttpOpenListener due to holding remote connections indefinitely may lead to denial of service.
References:
https://issues.redhat.com/browse/JBEAP-16695
Other sources
A flaw was found in Undertow when using Remoting as shipped in Red Hat Jboss EAP before version 7.2.4. A memory leak in HttpOpenListener due to holding remote connections indefinitely may lead to denial of service. Versions before undertow 2.0.25.SP1 and jboss-remoting 5.0.14.SP1 are believed to be vulnerable.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2019-19343?
CVE-2019-19343 is a vulnerability found in Undertow when using Remoting as shipped in Red Hat Jboss EAP before version 7.2.4.
What is the severity of CVE-2019-19343?
The severity of CVE-2019-19343 is medium, with a CVSS score of 5.9.
How does CVE-2019-19343 affect software?
CVE-2019-19343 affects Undertow versions before 2.0.25.SP1 and jboss-remoting versions before 5.0.14.SP1.
What is the impact of CVE-2019-19343?
CVE-2019-19343 can lead to a denial of service due to a memory leak in HttpOpenListener.
How can CVE-2019-19343 be fixed?
To fix CVE-2019-19343, upgrade to Undertow version 2.0.25.SP1 or later, and jboss-remoting version 5.0.14.SP1 or later.