CVE-2024-7885
published 2024-08-21CVE-2024-7885: A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue occurs…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.64%
83.9th percentile
A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue occurs when the parseProxyProtocolV1 method processes multiple requests on the same HTTP connection. As a result, different requests may share the same StringBuilder instance, potentially leading to information leakage between requests or responses. In some cases, a value from a previous request or response may be erroneously reused, which could lead to unintended data exposure. This issue primarily results in errors and connection termination but creates a risk of data leakage in multi-request environments.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | undertow | < undertow 2.3.18-1 (forky) | undertow 2.3.18-1 (forky) |
| redhat | data_grid | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_fuse | — | — |
| redhat | process_automation | — | — |
| redhat | single_sign-on | — | — |
| redhat | undertow | >= 0 < 2.3.18-1 | 2.3.18-1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Risk Matrix: Platform (Undertow) — CVE-2024-7885
vendor_oracle·2025-07-15·CVSS 7.5
CVE-2024-7885 [HIGH] Oracle Oracle Communications Risk Matrix: Platform (Undertow) — CVE-2024-7885
Oracle Oracle Communications Risk Matrix: Platform (Undertow) vulnerability
CVE: CVE-2024-7885
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2025 (JUL 2025)
Oracle
Oracle Oracle Communications Risk Matrix: Install (Undertow) — CVE-2024-7885
vendor_oracle·2025-01-15·CVSS 7.5
CVE-2024-7885 [HIGH] Oracle Oracle Communications Risk Matrix: Install (Undertow) — CVE-2024-7885
Oracle Oracle Communications Risk Matrix: Install (Undertow) vulnerability
CVE: CVE-2024-7885
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2025 (JAN 2025)
Red Hat
undertow: Improper State Management in Proxy Protocol parsing causes information leakage
vendor_redhat·2024-08-07·CVSS 7.5
CVE-2024-7885 [HIGH] CWE-362 undertow: Improper State Management in Proxy Protocol parsing causes information leakage
undertow: Improper State Management in Proxy Protocol parsing causes information leakage
A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue occurs when the parseProxyProtocolV1 method processes multiple requests on the same HTTP connection. As a result, different requests may share the same StringBuilder instance, potentially leading to information leakage between requests or responses. In some cases, a value from a previous request or response may be erroneously reused, which could lead to unintended data exposure. This issue primarily results in errors and connection termination but creates a risk of data leakage in multi-request environments.
A vulnerability was found in Undertow where t
Debian
CVE-2024-7885: undertow - A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses...
vendor_debian·2024·CVSS 7.5
CVE-2024-7885 [HIGH] CVE-2024-7885: undertow - A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses...
A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue occurs when the parseProxyProtocolV1 method processes multiple requests on the same HTTP connection. As a result, different requests may share the same StringBuilder instance, potentially leading to information leakage between requests or responses. In some cases, a value from a previous request or response may be erroneously reused, which could lead to unintended data exposure. This issue primarily results in errors and connection termination but creates a risk of data leakage in multi-request environments.
Scope: local
forky: resolved (fixed in 2.3.18-1)
sid: resolved (fixed in 2.3.18-1)
OSV
CVE-2024-7885: A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests
osv·2024-08-21·CVSS 7.5
CVE-2024-7885 [HIGH] CVE-2024-7885: A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests
A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue occurs when the parseProxyProtocolV1 method processes multiple requests on the same HTTP connection. As a result, different requests may share the same StringBuilder instance, potentially leading to information leakage between requests or responses. In some cases, a value from a previous request or response may be erroneously reused, which could lead to unintended data exposure. This issue primarily results in errors and connection termination but creates a risk of data leakage in multi-request environments.
OSV
Undertow vulnerable to Race Condition
osv·2024-08-21
CVE-2024-7885 [HIGH] Undertow vulnerable to Race Condition
Undertow vulnerable to Race Condition
A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue occurs when the parseProxyProtocolV1 method processes multiple requests on the same HTTP connection. As a result, different requests may share the same StringBuilder instance, potentially leading to information leakage between requests or responses. In some cases, a value from a previous request or response may be erroneously reused, which could lead to unintended data exposure. This issue primarily results in errors and connection termination but creates a risk of data leakage in multi-request environments.
GHSA
Undertow vulnerable to Race Condition
ghsa·2024-08-21
CVE-2024-7885 [HIGH] CWE-362 Undertow vulnerable to Race Condition
Undertow vulnerable to Race Condition
A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue occurs when the parseProxyProtocolV1 method processes multiple requests on the same HTTP connection. As a result, different requests may share the same StringBuilder instance, potentially leading to information leakage between requests or responses. In some cases, a value from a previous request or response may be erroneously reused, which could lead to unintended data exposure. This issue primarily results in errors and connection termination but creates a risk of data leakage in multi-request environments.
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2024:11023https://access.redhat.com/errata/RHSA-2024:6508https://access.redhat.com/errata/RHSA-2024:6883https://access.redhat.com/errata/RHSA-2024:7441https://access.redhat.com/errata/RHSA-2024:7442https://access.redhat.com/errata/RHSA-2024:7735https://access.redhat.com/errata/RHSA-2024:7736https://access.redhat.com/errata/RHSA-2024:8080https://access.redhat.com/errata/RHSA-2025:16667https://access.redhat.com/errata/RHSA-2026:0743https://access.redhat.com/security/cve/CVE-2024-7885https://bugzilla.redhat.com/show_bug.cgi?id=2305290https://security.netapp.com/advisory/ntap-20241011-0004/
2024-08-21
Published