REDHAT-BUG-1991299: High severity undertow vulnerability
A vulnerability was found in Undertow where buffer leak on incoming websocket PONG message may lead to memory exhaustion.
https://issues.redhat.com/browse/UNDERTOW-1935
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1991299?
The vulnerability REDHAT-BUG-1991299 is rated as a high severity issue due to potential memory exhaustion.
How do I fix REDHAT-BUG-1991299?
To address REDHAT-BUG-1991299, you should update to the latest version of Red Hat Undertow that contains the patch for this vulnerability.
What is the cause of REDHAT-BUG-1991299?
REDHAT-BUG-1991299 is caused by a buffer leak occurring on incoming websocket PONG messages, which can lead to memory exhaustion.
Which versions of Red Hat Undertow are affected by REDHAT-BUG-1991299?
Unfortunately, specific versions vulnerable to REDHAT-BUG-1991299 are not explicitly stated but typically recent releases are affected.
Are there any workarounds for REDHAT-BUG-1991299?
There are no recommended workarounds for REDHAT-BUG-1991299; updating to the patched version is the best approach.