CVE-2024-6162
published 2024-06-20CVE-2024-6162: A vulnerability was found in Undertow, where URL-encoded request paths can be mishandled during concurrent requests on the AJP listener. This issue arises…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.70%
74.6th percentile
A vulnerability was found in Undertow, where URL-encoded request paths can be mishandled during concurrent requests on the AJP listener. This issue arises because the same buffer is used to decode the paths for multiple requests simultaneously, leading to incorrect path information being processed. As a result, the server may attempt to access the wrong path, causing errors such as "404 Not Found" or other application failures. This flaw can potentially lead to a denial of service, as legitimate resources become inaccessible due to the path mix-up.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | undertow | < undertow 2.3.18-1 (forky) | undertow 2.3.18-1 (forky) |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Undertow's url-encoded request path information can be broken on ajp-listener
ghsa·2024-06-20
CVE-2024-6162 [HIGH] CWE-400 Undertow's url-encoded request path information can be broken on ajp-listener
Undertow's url-encoded request path information can be broken on ajp-listener
A vulnerability was found in Undertow, where URL-encoded request paths can be mishandled during concurrent requests on the AJP listener. This issue arises because the same buffer is used to decode the paths for multiple requests simultaneously, leading to incorrect path information being processed. As a result, the server may attempt to access the wrong path, causing errors such as "404 Not Found" or other application failures. This flaw can potentially lead to a denial of service, as legitimate resources become inaccessible due to the path mix-up.
OSV
CVE-2024-6162: A vulnerability was found in Undertow, where URL-encoded request paths can be mishandled during concurrent requests on the AJP listener
osv·2024-06-20·CVSS 7.5
CVE-2024-6162 [HIGH] CVE-2024-6162: A vulnerability was found in Undertow, where URL-encoded request paths can be mishandled during concurrent requests on the AJP listener
A vulnerability was found in Undertow, where URL-encoded request paths can be mishandled during concurrent requests on the AJP listener. This issue arises because the same buffer is used to decode the paths for multiple requests simultaneously, leading to incorrect path information being processed. As a result, the server may attempt to access the wrong path, causing errors such as "404 Not Found" or other application failures. This flaw can potentially lead to a denial of service, as legitimate resources become inaccessible due to the path mix-up.
OSV
Undertow's url-encoded request path information can be broken on ajp-listener
osv·2024-06-20
CVE-2024-6162 [HIGH] Undertow's url-encoded request path information can be broken on ajp-listener
Undertow's url-encoded request path information can be broken on ajp-listener
A vulnerability was found in Undertow, where URL-encoded request paths can be mishandled during concurrent requests on the AJP listener. This issue arises because the same buffer is used to decode the paths for multiple requests simultaneously, leading to incorrect path information being processed. As a result, the server may attempt to access the wrong path, causing errors such as "404 Not Found" or other application failures. This flaw can potentially lead to a denial of service, as legitimate resources become inaccessible due to the path mix-up.
Oracle
Oracle Oracle Communications Applications Risk Matrix: Security (Netty) — CVE-2024-6162
vendor_oracle·2025-01-15·CVSS 7.5
CVE-2024-6162 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Security (Netty) — CVE-2024-6162
Oracle Oracle Communications Applications Risk Matrix: Security (Netty) vulnerability
CVE: CVE-2024-6162
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2025 (JAN 2025)
Oracle
Oracle Oracle Communications Risk Matrix: Configuration (Undertow) — CVE-2024-6162
vendor_oracle·2024-10-15·CVSS 7.5
CVE-2024-6162 [HIGH] Oracle Oracle Communications Risk Matrix: Configuration (Undertow) — CVE-2024-6162
Oracle Oracle Communications Risk Matrix: Configuration (Undertow) vulnerability
CVE: CVE-2024-6162
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2024 (OCT 2024)
Oracle
Oracle Oracle Communications Risk Matrix: Install (Undertow) — CVE-2024-6162
vendor_oracle·2024-07-15·CVSS 7.5
CVE-2024-6162 [HIGH] Oracle Oracle Communications Risk Matrix: Install (Undertow) — CVE-2024-6162
Oracle Oracle Communications Risk Matrix: Install (Undertow) vulnerability
CVE: CVE-2024-6162
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2024 (JUL 2024)
Red Hat
undertow: url-encoded request path information can be broken on ajp-listener
vendor_redhat·2024-06-19·CVSS 7.5
CVE-2024-6162 [HIGH] CWE-488 undertow: url-encoded request path information can be broken on ajp-listener
undertow: url-encoded request path information can be broken on ajp-listener
A vulnerability was found in Undertow, where URL-encoded request paths can be mishandled during concurrent requests on the AJP listener. This issue arises because the same buffer is used to decode the paths for multiple requests simultaneously, leading to incorrect path information being processed. As a result, the server may attempt to access the wrong path, causing errors such as "404 Not Found" or other application failures. This flaw can potentially lead to a denial of service, as legitimate resources become inaccessible due to the path mix-up.
A vulnerability was found in Undertow, where URL-encoded request paths can be mishandled during concurrent requests on the AJP listener. This issue arises because the
Debian
CVE-2024-6162: undertow - A vulnerability was found in Undertow, where URL-encoded request paths can be mi...
vendor_debian·2024·CVSS 7.5
CVE-2024-6162 [HIGH] CVE-2024-6162: undertow - A vulnerability was found in Undertow, where URL-encoded request paths can be mi...
A vulnerability was found in Undertow, where URL-encoded request paths can be mishandled during concurrent requests on the AJP listener. This issue arises because the same buffer is used to decode the paths for multiple requests simultaneously, leading to incorrect path information being processed. As a result, the server may attempt to access the wrong path, causing errors such as "404 Not Found" or other application failures. This flaw can potentially lead to a denial of service, as legitimate resources become inaccessible due to the path mix-up.
Scope: local
forky: resolved (fixed in 2.3.18-1)
sid: resolved (fixed in 2.3.18-1)
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2024:1194https://access.redhat.com/errata/RHSA-2024:4386https://access.redhat.com/errata/RHSA-2024:4884https://access.redhat.com/security/cve/CVE-2024-6162https://bugzilla.redhat.com/show_bug.cgi?id=2293069https://issues.redhat.com/browse/JBEAP-26268https://access.redhat.com/errata/RHSA-2024:4884https://access.redhat.com/security/cve/CVE-2024-6162https://bugzilla.redhat.com/show_bug.cgi?id=2293069https://security.netapp.com/advisory/ntap-20241129-0009/
2024-06-20
Published