CVE-2023-1108
—CVSS 3.1
7.5 high
EPSS
2%p77
Published
()
Modified
Description
A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.
- Vendors
- redhatnetapp
- Products
- build of quarkus, decision manager, fuse, integration camel k, integration service registry, jboss enterprise application platform, jboss enterprise application platform expansion pack, openshift application runtimes, openstack platform, process automation, single sign-on, undertow
- Weakness
- CWE-835
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.