PT-2023-9531 · Undertow · Undertow

Pedro Sampaio

·

Published

2023-11-09

·

Updated

2026-02-25

·

CVE-2024-6162

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Undertow (affected versions not specified)
Description A vulnerability in Undertow's ajp-listener component is related to uncontrolled resource consumption due to incorrect decoding of request path information. This issue arises because the same buffer is used to decode the paths for multiple requests simultaneously, leading to incorrect path information being processed. As a result, the server may attempt to access the wrong path, causing errors such as "404 Not Found" or other application failures. This flaw can potentially lead to a denial of service, as legitimate resources become inaccessible due to the path mix-up.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Race Condition

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BDU:2024-08258
CVE-2024-6162
GHSA-9442-GM4V-R222

Affected Products

Undertow