PT-2023-32078 · Red Hat+1 · Mod Cluster+4
Patrick Del Bello
·
Published
2023-12-12
·
Updated
2025-10-25
·
CVE-2023-5379
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
JBoss EAP (affected versions not specified)
Description
A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error state by mod cluster in httpd, causing JBoss EAP to close the TCP connection without returning an AJP response. This happens because mod proxy cluster marks the JBoss EAP instance as an error worker when the TCP connection is closed from the backend after sending the AJP request without receiving an AJP response, and stops forwarding. This issue could allow a malicious user to repeatedly send requests that exceed the max-header-size, causing a Denial of Service (DoS).
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jboss Eap
Undertow
Httpd
Mod Cluster
Mod Proxy Cluster