Redhat Jboss-Remoting vulnerabilities
2 known vulnerabilities affecting redhat/jboss-remoting.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2020-35510MEDIUMCVSS 5.9fixed in 5.0.20v5.0.202021-06-02
CVE-2020-35510 [MEDIUM] CWE-400 CVE-2020-35510: A flaw was found in jboss-remoting in versions before 5.0.20.SP1-redhat-00001. A malicious attacker
A flaw was found in jboss-remoting in versions before 5.0.20.SP1-redhat-00001. A malicious attacker could cause threads to hold up forever in the EJB server by writing a sequence of bytes corresponding to the expected messages of a successful EJB client request, but omitting the ACK messages, or just tamper with jboss-remoting code, deleting the line
nvd
CVE-2019-19343HIGHCVSS 7.5fixed in 5.0.14v5.0.142021-03-23
CVE-2019-19343 [HIGH] CWE-400 CVE-2019-19343: A flaw was found in Undertow when using Remoting as shipped in Red Hat Jboss EAP before version 7.2.
A flaw was found in Undertow when using Remoting as shipped in Red Hat Jboss EAP before version 7.2.4. A memory leak in HttpOpenListener due to holding remote connections indefinitely may lead to denial of service. Versions before undertow 2.0.25.SP1 and jboss-remoting 5.0.14.SP1 are believed to be vulnerable.
nvd