CVE-2022-2764: Medium severity red hat integration - camel k vulnerability
A flaw was found in Undertow with EJB invocations. This flaw allows an attacker to generate a valid HTTP request and send it to the server on an established connection after removing the LASTCHUNK from the bytes, causing a denial of service.
Other sources
A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LASTCHUNK forever for EJB invocations.
UndertowInputStream.close() blocks waiting to read -1
https://issues.redhat.com/browse/UNDERTOW-2048
— Red Hat
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-2764?
CVE-2022-2764 is a vulnerability found in Undertow with EJB invocations that allows an attacker to generate a valid HTTP request and send it to the server, causing a denial of service.
Which software versions are affected by CVE-2022-2764?
The affected software versions include eap7-undertow 2.2.20-1.SP1_redhat_00001.1.el7ea, eap7-undertow 2.2.20-1.SP1_redhat_00001.1.el8ea, eap7-undertow 2.2.20-1.SP1_redhat_00001.1.el9ea, rh-sso7-keycloak 18.0.6-1.redhat_00001.1.el7, rh-sso7-keycloak 18.0.6-1.redhat_00001.1.el8, and rh-sso7-keycloak 18.0.6-1.redhat_00001.1.el9.
How severe is CVE-2022-2764?
CVE-2022-2764 has a severity level of medium.
What is the remedy for CVE-2022-2764?
The remedy for CVE-2022-2764 is to update eap7-undertow to version 2.2.20-1.SP1_redhat_00001.1.el7ea, 2.2.20-1.SP1_redhat_00001.1.el8ea, or 2.2.20-1.SP1_redhat_00001.1.el9ea, and update rh-sso7-keycloak to version 18.0.6-1.redhat_00001.1.el7, 18.0.6-1.redhat_00001.1.el8, or 18.0.6-1.redhat_00001.1.el9.
Where can I find more information about CVE-2022-2764?
You can find more information about CVE-2022-2764 at the following references: [link1], [link2], and [link3].