ZeroHour

CVE-2023-1108

CVSS 3.1
7.5 high
EPSS
2%p77
Published
()
Modified
Description

A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.

Vendors
redhatnetapp
Products
build of quarkus, decision manager, fuse, integration camel k, integration service registry, jboss enterprise application platform, jboss enterprise application platform expansion pack, openshift application runtimes, openstack platform, process automation, single sign-on, undertow
Weakness
CWE-835
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.