REDHAT-BUG-2276410: High severity Eclipse Undertow vulnerability
There exists a security vulnerability in Undertow that can cause remote DoS attacks. Servlets using method that calls HttpServletRequestImpl.getParameterNames() will cause OutOfMemoryError when the client sends a request with huge parameter names. This vulnerability can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack.
Affected Software
Event History
Frequently Asked Questions
What is the risk level of REDHAT-BUG-2276410?
The risk level of REDHAT-BUG-2276410 is assessed as 33.
What is the severity of REDHAT-BUG-2276410?
The severity of REDHAT-BUG-2276410 is classified as high, with a score of 7.
What vulnerability is associated with REDHAT-BUG-2276410?
REDHAT-BUG-2276410 describes a security vulnerability in Undertow that can lead to remote denial of service (DoS) attacks due to OutOfMemoryError.
How can I mitigate REDHAT-BUG-2276410?
Mitigation strategies for REDHAT-BUG-2276410 include validating input and limiting the size of parameter names handled by servlets.
What version of Eclipse Undertow is affected by REDHAT-BUG-2276410?
Eclipse Undertow versions that utilize the method calling HttpServletRequestImpl.getParameterNames() are affected by REDHAT-BUG-2276410.