CVE-2023-1108
published 2023-09-14CVE-2023-1108: A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the…
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.77%
75.8th percentile
A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | undertow | < undertow 2.3.8-2 (forky) | undertow 2.3.8-2 (forky) |
| redhat | decision_manager | — | — |
| redhat | fuse | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform_for_linuxone | — | — |
| redhat | openshift_container_platform_for_linuxone | — | — |
| redhat | openshift_container_platform_for_power | — | — |
| redhat | openshift_container_platform_for_power | — | — |
| redhat | openstack_platform | — | — |
| redhat | process_automation | — | — |
| redhat | single_sign-on | — | — |
| redhat | undertow | < 2.2.24 | 2.2.24 |
| redhat | undertow | >= 0 < 2.3.8-2 | 2.3.8-2 |
| redhat | undertow | >= 2.3.0 < 2.3.5 | 2.3.5 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Undertow denial of service vulnerability
ghsa·2023-09-14
CVE-2023-1108 [HIGH] CWE-835 Undertow denial of service vulnerability
Undertow denial of service vulnerability
A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.
OSV
Undertow denial of service vulnerability
osv·2023-09-14
CVE-2023-1108 [HIGH] Undertow denial of service vulnerability
Undertow denial of service vulnerability
A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.
OSV
CVE-2023-1108: A flaw was found in undertow
osv·2023-09-14·CVSS 7.5
CVE-2023-1108 [HIGH] CVE-2023-1108: A flaw was found in undertow
A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.
Oracle
Oracle Oracle Communications Risk Matrix: Signaling (Undertow) — CVE-2023-1108
vendor_oracle·2024-01-15·CVSS 7.5
CVE-2023-1108 [HIGH] Oracle Oracle Communications Risk Matrix: Signaling (Undertow) — CVE-2023-1108
Oracle Oracle Communications Risk Matrix: Signaling (Undertow) vulnerability
CVE: CVE-2023-1108
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2024 (JAN 2024)
Red Hat
Undertow: Infinite loop in SslConduit during close
vendor_redhat·2023-03-07·CVSS 7.5
CVE-2023-1108 [HIGH] CWE-835 Undertow: Infinite loop in SslConduit during close
Undertow: Infinite loop in SslConduit during close
A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.
A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.
Package: undertow (Red Hat build of Apicurio Registry 2) - Affected
Package: io.quarkus/quarkus-undertow (Red Hat build of Quarkus) - Not affected
Package: undertow (Red Hat Data Grid 8) - Not affected
Package: undertow (Red Hat Integration Camel K 1) - Affected
Package: undertow (Red Hat Integration Camel Quarkus 1) - Not affected
Package: undertow (Red Hat JBoss Data Grid 7) -
Debian
CVE-2023-1108: undertow - A flaw was found in undertow. This issue makes achieving a denial of service pos...
vendor_debian·2023·CVSS 7.5
CVE-2023-1108 [HIGH] CVE-2023-1108: undertow - A flaw was found in undertow. This issue makes achieving a denial of service pos...
A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.
Scope: local
forky: resolved (fixed in 2.3.8-2)
sid: resolved (fixed in 2.3.8-2)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2023:1184https://access.redhat.com/errata/RHSA-2023:1185https://access.redhat.com/errata/RHSA-2023:1512https://access.redhat.com/errata/RHSA-2023:1513https://access.redhat.com/errata/RHSA-2023:1514https://access.redhat.com/errata/RHSA-2023:1516https://access.redhat.com/errata/RHSA-2023:2135https://access.redhat.com/errata/RHSA-2023:3883https://access.redhat.com/errata/RHSA-2023:3884https://access.redhat.com/errata/RHSA-2023:3885https://access.redhat.com/errata/RHSA-2023:3888https://access.redhat.com/errata/RHSA-2023:3892https://access.redhat.com/errata/RHSA-2023:3954https://access.redhat.com/errata/RHSA-2023:4612https://access.redhat.com/security/cve/CVE-2023-1108https://bugzilla.redhat.com/show_bug.cgi?id=2174246https://github.com/advisories/GHSA-m4mm-pg93-fv78https://security.netapp.com/advisory/ntap-20231020-0002/https://access.redhat.com/errata/RHSA-2023:1184https://access.redhat.com/errata/RHSA-2023:1185https://access.redhat.com/errata/RHSA-2023:1512https://access.redhat.com/errata/RHSA-2023:1513https://access.redhat.com/errata/RHSA-2023:1514https://access.redhat.com/errata/RHSA-2023:1516https://access.redhat.com/errata/RHSA-2023:2135https://access.redhat.com/errata/RHSA-2023:3883https://access.redhat.com/errata/RHSA-2023:3884https://access.redhat.com/errata/RHSA-2023:3885https://access.redhat.com/errata/RHSA-2023:3888https://access.redhat.com/errata/RHSA-2023:3892https://access.redhat.com/errata/RHSA-2023:3954https://access.redhat.com/errata/RHSA-2023:4612https://access.redhat.com/security/cve/CVE-2023-1108https://bugzilla.redhat.com/show_bug.cgi?id=2174246https://github.com/advisories/GHSA-m4mm-pg93-fv78https://security.netapp.com/advisory/ntap-20231020-0002/
2023-09-14
Published