PT-2023-32078 · Apache+1 · Httpd+4

·

CVE-2023-5379

·

Publicado

2023-12-12

·

Atualizado

2025-10-25

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions JBoss EAP (affected versions not specified)
Description A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error state by mod cluster in httpd, causing JBoss EAP to close the TCP connection without returning an AJP response. This happens because mod proxy cluster marks the JBoss EAP instance as an error worker when the TCP connection is closed from the backend after sending the AJP request without receiving an AJP response, and stops forwarding. This issue could allow a malicious user to repeatedly send requests that exceed the max-header-size, causing a Denial of Service (DoS).
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Allocation of Resources Without Limits

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-5379
OESA-2024-2353
RHSA-2025:9582
RHSA-2025:9583

Produtos afetados

Jboss Eap
Undertow
Httpd
Mod Cluster
Mod Proxy Cluster