Back

MEDIUM

undertow: Infoleak in some circumstances where Undertow can serve data from a random buffer

Published Sep 18, 2018

Description

An information leak vulnerability was found in Undertow. If all headers are not written out in the first write() call then the code that handles flushing the buffer will always write out the full contents of the writevBuffer buffer, which may contain data from previous requests.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Sep 18, 2018
Updated Aug 5, 2024
Reserved Jul 27, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Sep 14, 2018
GHSA-VF6R-MMHC-3XCM