CVE-2022-1319: High severity red hat openshift application runtimes vulnerability
A flaw was found in Undertow. For an AJP 400 response, EAP 7 is improperly sending two response packets, and those packets have the reuse flag set even though JBoss EAP closes the connection. A failure occurs when the connection is reused after a 400 by CPING since it reads in the second SENDHEADERS response packet instead of a CPONG.
Other sources
For an AJP 400 response, EAP 7 is improperly sending two response packets and those 'END RESPONSE' packets have the reuse flag set even though JBoss does close the connection. So when httpd reuses that connection after a 400 for something like a cping, it will receive a failure since it reads in the second SENDHEADERS response packet instead of a CPONG.
— Red Hat
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID of this flaw?
The vulnerability ID of this flaw is CVE-2022-1319.
What is the severity level of CVE-2022-1319?
The severity level of CVE-2022-1319 is high with a score of 7.5.
How does EAP 7 handle the AJP 400 response in CVE-2022-1319?
EAP 7 improperly sends two response packets for an AJP 400 response, which causes a failure when the connection is reused.
Which software packages are affected by CVE-2022-1319?
The affected software packages include eap7-undertow, rh-sso7-keycloak, Redhat Openshift Application Runtimes, Redhat Single Sign-on, and Netapp Active Iq Unified Manager.
How can I fix CVE-2022-1319?
Apply the appropriate security updates provided by the vendor to fix CVE-2022-1319.