CVE-2024-3653
published 2024-07-08CVE-2024-3653: A vulnerability was found in Undertow. This issue requires enabling the learning-push handler in the server's config, which is disabled by default, leaving the…
PriorityP430medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
1.87%
76.9th percentile
A vulnerability was found in Undertow. This issue requires enabling the learning-push handler in the server's config, which is disabled by default, leaving the maxAge config in the handler unconfigured. The default is -1, which makes the handler vulnerable. If someone overwrites that config, the server is not subject to the attack. The attacker needs to be able to reach the server with a normal HTTP request.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | undertow | < undertow 2.3.18-1 (forky) | undertow 2.3.18-1 (forky) |
| redhat | undertow | >= 0 < 2.3.18-1 | 2.3.18-1 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Undertow Missing Release of Memory after Effective Lifetime vulnerability
ghsa·2024-07-09
CVE-2024-3653 [MEDIUM] CWE-401 Undertow Missing Release of Memory after Effective Lifetime vulnerability
Undertow Missing Release of Memory after Effective Lifetime vulnerability
A vulnerability was found in Undertow. This issue requires enabling the learning-push handler in the server's config, which is disabled by default, leaving the maxAge config in the handler unconfigured. The default is -1, which makes the handler vulnerable. If someone overwrites that config, the server is not subject to the attack. The attacker needs to be able to reach the server with a normal HTTP request.
OSV
Undertow Missing Release of Memory after Effective Lifetime vulnerability
osv·2024-07-09
CVE-2024-3653 [MEDIUM] Undertow Missing Release of Memory after Effective Lifetime vulnerability
Undertow Missing Release of Memory after Effective Lifetime vulnerability
A vulnerability was found in Undertow. This issue requires enabling the learning-push handler in the server's config, which is disabled by default, leaving the maxAge config in the handler unconfigured. The default is -1, which makes the handler vulnerable. If someone overwrites that config, the server is not subject to the attack. The attacker needs to be able to reach the server with a normal HTTP request.
OSV
CVE-2024-3653: A vulnerability was found in Undertow
osv·2024-07-08·CVSS 5.3
CVE-2024-3653 [MEDIUM] CVE-2024-3653: A vulnerability was found in Undertow
A vulnerability was found in Undertow. This issue requires enabling the learning-push handler in the server's config, which is disabled by default, leaving the maxAge config in the handler unconfigured. The default is -1, which makes the handler vulnerable. If someone overwrites that config, the server is not subject to the attack. The attacker needs to be able to reach the server with a normal HTTP request.
Red Hat
undertow: LearningPushHandler can lead to remote memory DoS attacks
vendor_redhat·2024-07-08·CVSS 5.3
CVE-2024-3653 [MEDIUM] CWE-401 undertow: LearningPushHandler can lead to remote memory DoS attacks
undertow: LearningPushHandler can lead to remote memory DoS attacks
A vulnerability was found in Undertow. This issue requires enabling the learning-push handler in the server's config, which is disabled by default, leaving the maxAge config in the handler unconfigured. The default is -1, which makes the handler vulnerable. If someone overwrites that config, the server is not subject to the attack. The attacker needs to be able to reach the server with a normal HTTP request.
A vulnerability was found in Undertow. This issue requires enabling the learning-push handler in the server's config, which is disabled by default, leaving the maxAge config in the handler unconfigured. The default is -1, which makes the handler vulnerable. If someone overwrites that config, the server is not subject
Debian
CVE-2024-3653: undertow - A vulnerability was found in Undertow. This issue requires enabling the learning...
vendor_debian·2024·CVSS 5.3
CVE-2024-3653 [MEDIUM] CVE-2024-3653: undertow - A vulnerability was found in Undertow. This issue requires enabling the learning...
A vulnerability was found in Undertow. This issue requires enabling the learning-push handler in the server's config, which is disabled by default, leaving the maxAge config in the handler unconfigured. The default is -1, which makes the handler vulnerable. If someone overwrites that config, the server is not subject to the attack. The attacker needs to be able to reach the server with a normal HTTP request.
Scope: local
forky: resolved (fixed in 2.3.18-1)
sid: resolved (fixed in 2.3.18-1)
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2024:4392https://access.redhat.com/errata/RHSA-2024:5143https://access.redhat.com/errata/RHSA-2024:5144https://access.redhat.com/errata/RHSA-2024:5145https://access.redhat.com/errata/RHSA-2024:5147https://access.redhat.com/errata/RHSA-2024:6437https://access.redhat.com/security/cve/CVE-2024-3653https://bugzilla.redhat.com/show_bug.cgi?id=2274437https://access.redhat.com/errata/RHSA-2024:4392https://access.redhat.com/security/cve/CVE-2024-3653https://bugzilla.redhat.com/show_bug.cgi?id=2274437https://security.netapp.com/advisory/ntap-20240828-0002/
2024-07-08
Published