Logo
vuln-group

GHSA-m4mm-pg93-fv78

Severity: high (7.5)

First published: Thu Sep 14 2023

Last modified: Thu Sep 21 2023

CWE: 835

A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.

Any of

  • maven/io.undertow:undertow-core
    <2.2.24.Final
    fixed in: 2.2.24.Final
  • maven/io.undertow:undertow-core
    >=2.3.0<2.3.5.Final
    fixed in: 2.3.5.Final
SecAlerts Pty Ltd.
Fortitude Valley,
QLD 4006, Australia
© Copyright 2023 - ABN: 70 645 966 203, ACN: 645 966 203