Undertow: Memory Leak in Undertow HttpOpenListener due to holding remoting connections indefinitely
Published Mar 23, 2021
7.5
HIGHCVSS 3.1
EPSS 1.63%
Description
A flaw was found in Undertow when using Remoting as shipped in Red Hat Jboss EAP before version 7.2.4. A memory leak in HttpOpenListener due to holding remote connections indefinitely may lead to denial of service. Versions before undertow 2.0.25.SP1 and jboss-remoting 5.0.14.SP1 are believed to be vulnerable.
Affected products
- Vendor n/a Product Undertow Defaultunknown
Affected
- undertow 2.0.25.SP1, jboss-remoting 5.0.14.SP1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | Undertow | unknown | Affected
|
Configuration 1
- < 5.0.14
- 5.0.14
- < 7.2.4
- < 2.0.25
- 2.0.25
Configuration 2
- n/a
- n/a
- n/a
No data.
Red Hat Fuse 7.8.0
undertow
Fixed · RHSA-2020:5568
Red Hat JBoss EAP 7.2
n/a
Fixed · RHSA-2019:2938
Red Hat JBoss Enterprise Application Platform Continuous Delivery
undertow
Fixed · RHSA-2020:2565
Red Hat Decision Manager 7
undertow
Not affected
Red Hat JBoss Data Grid 7
undertow
Not affected
Red Hat JBoss Enterprise Application Platform 7
undertow
Affected
Red Hat JBoss Fuse 6
undertow
Out of support scope
Red Hat OpenShift Application Runtimes
undertow
Out of support scope
Red Hat Process Automation 7
undertow
Not affected
Red Hat Single Sign-On 7
undertow
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Fuse 7.8.0 | undertow | Fixed | RHSA-2020:5568 |
| Red Hat JBoss EAP 7.2 | n/a | Fixed | RHSA-2019:2938 |
| Red Hat JBoss Enterprise Application Platform Continuous Delivery | undertow | Fixed | RHSA-2020:2565 |
| Red Hat Decision Manager 7 | undertow | Not affected | n/a |
| Red Hat JBoss Data Grid 7 | undertow | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | undertow | Affected | n/a |
| Red Hat JBoss Fuse 6 | undertow | Out of support scope | n/a |
| Red Hat OpenShift Application Runtimes | undertow | Out of support scope | n/a |
| Red Hat Process Automation 7 | undertow | Not affected | n/a |
| Red Hat Single Sign-On 7 | undertow | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (7)
- https://access.redhat.com/security/cve/CVE-2019-19343 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1780445 x_refsource_MISCIssue TrackingVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-8964 Advisory
- https://issues.redhat.com/browse/JBEAP-16695 x_refsource_MISCPermissions RequiredVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-19343
- https://security.netapp.com/advisory/ntap-20220211-0002/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-19343
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-19343 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1780445 | x_refsource_MISCIssue TrackingVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-8964 | Advisory | |
| https://issues.redhat.com/browse/JBEAP-16695 | x_refsource_MISCPermissions RequiredVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-19343 | ||
| https://security.netapp.com/advisory/ntap-20220211-0002/ | x_refsource_CONFIRMThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2019-19343 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data