PT-2023-32078 · Red Hat+1 · Mod Cluster+4

Patrick Del Bello

·

Published

2023-12-12

·

Updated

2025-10-25

·

CVE-2023-5379

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions JBoss EAP (affected versions not specified)
Description A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error state by mod cluster in httpd, causing JBoss EAP to close the TCP connection without returning an AJP response. This happens because mod proxy cluster marks the JBoss EAP instance as an error worker when the TCP connection is closed from the backend after sending the AJP request without receiving an AJP response, and stops forwarding. This issue could allow a malicious user to repeatedly send requests that exceed the max-header-size, causing a Denial of Service (DoS).
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2023-5379
OESA-2024-2353
RHSA-2025:9582
RHSA-2025:9583

Affected Products

Jboss Eap
Undertow
Httpd
Mod Cluster
Mod Proxy Cluster