CVE-2019-14888
published 2020-01-23CVE-2019-14888: A vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listening on HTTPS. An attacker can target the HTTPS port to carry out…
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.14%
80.0th percentile
A vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listening on HTTPS. An attacker can target the HTTPS port to carry out a Denial Of Service (DOS) to make the service unavailable on SSL.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | undertow | < undertow 2.0.30-1 (forky) | undertow 2.0.30-1 (forky) |
| red_hat | undertow | — | — |
| redhat | jboss_data_grid | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_fuse | — | — |
| redhat | jboss_fuse | — | — |
| redhat | single_sign-on | — | — |
| redhat | undertow | <= 2.0.28 | — |
| redhat | undertow | >= 0 < 2.0.30-1 | 2.0.30-1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
undertow: possible Denial Of Service (DOS) in Undertow HTTP server listening on HTTPS
vendor_redhat·2020-01-20·CVSS 7.5
CVE-2019-14888 [HIGH] CWE-400 undertow: possible Denial Of Service (DOS) in Undertow HTTP server listening on HTTPS
undertow: possible Denial Of Service (DOS) in Undertow HTTP server listening on HTTPS
A vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listening on HTTPS. An attacker can target the HTTPS port to carry out a Denial Of Service (DOS) to make the service unavailable on SSL.
A vulnerability was found in the Undertow HTTP server listening on HTTPS. An attacker can target the HTTPS port to carry out a Denial Of Service (DOS) to make the service unavailable on SSL.
Mitigation: Enable HTTP2 (enable-http2="true") in the undertow's HTTPS settings.
Package: undertow (Red Hat Decision Manager 7) - Not affected
Package: undertow (Red Hat JBoss Fuse 6) - Affected
Package: undertow (Red Hat OpenShift Application Runtimes) - Affected
Package: undertow (Red Ha
Debian
CVE-2019-14888: undertow - A vulnerability was found in the Undertow HTTP server in versions before 2.0.28....
vendor_debian·2019·CVSS 7.5
CVE-2019-14888 [HIGH] CVE-2019-14888: undertow - A vulnerability was found in the Undertow HTTP server in versions before 2.0.28....
A vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listening on HTTPS. An attacker can target the HTTPS port to carry out a Denial Of Service (DOS) to make the service unavailable on SSL.
Scope: local
forky: resolved (fixed in 2.0.30-1)
sid: resolved (fixed in 2.0.30-1)
GHSA
Undertow vulnerable to Uncontrolled Resource Consumption
ghsa·2022-05-24
CVE-2019-14888 [HIGH] CWE-400 Undertow vulnerable to Uncontrolled Resource Consumption
Undertow vulnerable to Uncontrolled Resource Consumption
A vulnerability was found in the Undertow HTTP server in versions before 2.0.29 when listening on HTTPS. An attacker can target the HTTPS port to carry out a Denial Of Service (DOS) to make the service unavailable on SSL.
OSV
Undertow vulnerable to Uncontrolled Resource Consumption
osv·2022-05-24
CVE-2019-14888 [HIGH] Undertow vulnerable to Uncontrolled Resource Consumption
Undertow vulnerable to Uncontrolled Resource Consumption
A vulnerability was found in the Undertow HTTP server in versions before 2.0.29 when listening on HTTPS. An attacker can target the HTTPS port to carry out a Denial Of Service (DOS) to make the service unavailable on SSL.
OSV
CVE-2019-14888: A vulnerability was found in the Undertow HTTP server in versions before 2
osv·2020-01-23·CVSS 7.5
CVE-2019-14888 [HIGH] CVE-2019-14888: A vulnerability was found in the Undertow HTTP server in versions before 2
A vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listening on HTTPS. An attacker can target the HTTPS port to carry out a Denial Of Service (DOS) to make the service unavailable on SSL.
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2020:0729https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14888https://security.netapp.com/advisory/ntap-20220211-0001/https://access.redhat.com/errata/RHSA-2020:0729https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14888https://security.netapp.com/advisory/ntap-20220211-0001/
2020-01-23
Published