PT-2020-5137 · Red Hat · Undertow Http Server
Published
2020-01-23
·
Updated
2022-05-24
·
CVE-2019-14888
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Undertow HTTP server versions prior to 2.0.29
Description
A vulnerability in the Undertow HTTP server allows an attacker to carry out a Denial Of Service (DOS) attack by targeting the HTTPS port, making the service unavailable on SSL. This issue is related to an uncontrolled resource consumption.
Recommendations
For versions prior to 2.0.29, update to version 2.0.29 or later to resolve the issue. As a temporary workaround, consider restricting access to the HTTPS port to minimize the risk of exploitation.
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Undertow Http Server