CVE-2017-2670
published 2018-07-27CVE-2017-2670: It was found in Undertow before 1.3.28 that with non-clean TCP close, the Websocket server gets into infinite loop on every IO thread, effectively causing DoS.
PriorityP337high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
3.66%
88.4th percentile
It was found in Undertow before 1.3.28 that with non-clean TCP close, the Websocket server gets into infinite loop on every IO thread, effectively causing DoS.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | undertow | < undertow 1.4.18-1 (forky) | undertow 1.4.18-1 (forky) |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | undertow | < 1.3.28 | 1.3.28 |
| redhat | undertow | >= 0 < 1.4.18-1 | 1.4.18-1 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Moderate severity vulnerability that affects io.undertow:undertow-core
ghsa·2018-10-19
CVE-2017-2670 [MEDIUM] CWE-835 Moderate severity vulnerability that affects io.undertow:undertow-core
Moderate severity vulnerability that affects io.undertow:undertow-core
It was found in Undertow before 1.3.28 that with non-clean TCP close, the Websocket server gets into infinite loop on every IO thread, effectively causing DoS.
OSV
Moderate severity vulnerability that affects io.undertow:undertow-core
osv·2018-10-19
CVE-2017-2670 [MEDIUM] Moderate severity vulnerability that affects io.undertow:undertow-core
Moderate severity vulnerability that affects io.undertow:undertow-core
It was found in Undertow before 1.3.28 that with non-clean TCP close, the Websocket server gets into infinite loop on every IO thread, effectively causing DoS.
OSV
CVE-2017-2670: It was found in Undertow before 1
osv·2018-07-27·CVSS 7.5
CVE-2017-2670 [HIGH] CVE-2017-2670: It was found in Undertow before 1
It was found in Undertow before 1.3.28 that with non-clean TCP close, the Websocket server gets into infinite loop on every IO thread, effectively causing DoS.
Red Hat
undertow: IO thread DoS via unclean Websocket closing
vendor_redhat·2017-06-07·CVSS 7.5
CVE-2017-2670 [HIGH] CWE-835 undertow: IO thread DoS via unclean Websocket closing
undertow: IO thread DoS via unclean Websocket closing
It was found in Undertow before 1.3.28 that with non-clean TCP close, the Websocket server gets into infinite loop on every IO thread, effectively causing DoS.
It was found that with non-clean TCP close, Websocket server gets into infinite loop on every IO thread, effectively causing DoS.
Package: karaf (Red Hat Fuse 7) - Affected
Package: undertow (Red Hat JBoss Data Grid 7) - Affected
Package: karaf (Red Hat JBoss Fuse 6) - Will not fix
Package: undertow (Red Hat JBoss Fuse Integration Service 2) - Affected
Package: wildfly (Red Hat Single Sign-On 7) - Affected
Debian
CVE-2017-2670: undertow - It was found in Undertow before 1.3.28 that with non-clean TCP close, the Websoc...
vendor_debian·2017·CVSS 7.5
CVE-2017-2670 [HIGH] CVE-2017-2670: undertow - It was found in Undertow before 1.3.28 that with non-clean TCP close, the Websoc...
It was found in Undertow before 1.3.28 that with non-clean TCP close, the Websocket server gets into infinite loop on every IO thread, effectively causing DoS.
Scope: local
forky: resolved (fixed in 1.4.18-1)
sid: resolved (fixed in 1.4.18-1)
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2017-1409.htmlhttp://www.securityfocus.com/bid/98965https://access.redhat.com/errata/RHSA-2017:1410https://access.redhat.com/errata/RHSA-2017:1411https://access.redhat.com/errata/RHSA-2017:1412https://access.redhat.com/errata/RHSA-2017:3454https://access.redhat.com/errata/RHSA-2017:3455https://access.redhat.com/errata/RHSA-2017:3456https://access.redhat.com/errata/RHSA-2017:3458https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2670https://www.debian.org/security/2017/dsa-3906http://rhn.redhat.com/errata/RHSA-2017-1409.htmlhttp://www.securityfocus.com/bid/98965https://access.redhat.com/errata/RHSA-2017:1410https://access.redhat.com/errata/RHSA-2017:1411https://access.redhat.com/errata/RHSA-2017:1412https://access.redhat.com/errata/RHSA-2017:3454https://access.redhat.com/errata/RHSA-2017:3455https://access.redhat.com/errata/RHSA-2017:3456https://access.redhat.com/errata/RHSA-2017:3458https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2670https://www.debian.org/security/2017/dsa-3906
2018-07-27
Published