Undertow: DoS can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations
Published Sep 1, 2022
4.9
MEDIUMCVSS 3.1
EPSS 0.89%
Description
A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations.
Affected products
- Vendor n/a Product Undertow Defaultn/a
- Version undertow 2.xStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Undertow | n/a |
|
Configuration 1
- n/a
- 7.0.0
- 7.0.0
- 7.0
- ≥ 2.0.0 · ≤ 2.2.19
- 2.3.0
- 2.3.0
Configuration 2
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
No data.
RHEL-8 based Middleware Containers
rh-sso-7/sso76-openshift-rhel8:7.6-20
Fixed · RHSA-2023:1047
Red Hat JBoss Enterprise Application Platform
io.undertow/undertow-core:2.2.20.SP1-redhat-00001
Fixed · RHSA-2022:8793
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8
eap7-undertow-0:2.2.20-1.SP1_redhat_00001.1.el8eap
Fixed · RHSA-2022:8791
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9
eap7-undertow-0:2.2.20-1.SP1_redhat_00001.1.el9eap
Fixed · RHSA-2022:8792
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7
eap7-undertow-0:2.2.20-1.SP1_redhat_00001.1.el7eap
Fixed · RHSA-2022:8790
Red Hat Single Sign-On 7
undertow
Fixed · RHSA-2023:1049
Red Hat Single Sign-On 7.6 for RHEL 7
rh-sso7-keycloak-0:18.0.6-1.redhat_00001.1.el7sso
Fixed · RHSA-2023:1043
Red Hat Single Sign-On 7.6 for RHEL 8
rh-sso7-keycloak-0:18.0.6-1.redhat_00001.1.el8sso
Fixed · RHSA-2023:1044
Red Hat Single Sign-On 7.6 for RHEL 9
rh-sso7-keycloak-0:18.0.6-1.redhat_00001.1.el9sso
Fixed · RHSA-2023:1045
Red Hat Data Grid 8
undertow
Fix deferred
Red Hat Decision Manager 7
undertow
Not affected
Red Hat Fuse 7
undertow
Fix deferred
Red Hat Integration Camel K 1
undertow
Fix deferred
Red Hat Integration Camel Quarkus 1
undertow
Fix deferred
Red Hat Integration Service Registry
undertow
Not affected
Red Hat JBoss Data Grid 7
undertow
Out of support scope
Red Hat JBoss Fuse 6
undertow
Out of support scope
Red Hat OpenStack Platform 13 (Queens)
undertow
Out of support scope
Red Hat Process Automation 7
undertow
Not affected
Red Hat build of Quarkus
quarkus-http
Not affected
Red Hat build of Quarkus
undertow
Not affected
Red Hat support for Spring Boot
undertow
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| RHEL-8 based Middleware Containers | rh-sso-7/sso76-openshift-rhel8:7.6-20 | Fixed | RHSA-2023:1047 |
| Red Hat JBoss Enterprise Application Platform | io.undertow/undertow-core:2.2.20.SP1-redhat-00001 | Fixed | RHSA-2022:8793 |
| Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 | eap7-undertow-0:2.2.20-1.SP1_redhat_00001.1.el8eap | Fixed | RHSA-2022:8791 |
| Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 | eap7-undertow-0:2.2.20-1.SP1_redhat_00001.1.el9eap | Fixed | RHSA-2022:8792 |
| Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 | eap7-undertow-0:2.2.20-1.SP1_redhat_00001.1.el7eap | Fixed | RHSA-2022:8790 |
| Red Hat Single Sign-On 7 | undertow | Fixed | RHSA-2023:1049 |
| Red Hat Single Sign-On 7.6 for RHEL 7 | rh-sso7-keycloak-0:18.0.6-1.redhat_00001.1.el7sso | Fixed | RHSA-2023:1043 |
| Red Hat Single Sign-On 7.6 for RHEL 8 | rh-sso7-keycloak-0:18.0.6-1.redhat_00001.1.el8sso | Fixed | RHSA-2023:1044 |
| Red Hat Single Sign-On 7.6 for RHEL 9 | rh-sso7-keycloak-0:18.0.6-1.redhat_00001.1.el9sso | Fixed | RHSA-2023:1045 |
| Red Hat Data Grid 8 | undertow | Fix deferred | n/a |
| Red Hat Decision Manager 7 | undertow | Not affected | n/a |
| Red Hat Fuse 7 | undertow | Fix deferred | n/a |
| Red Hat Integration Camel K 1 | undertow | Fix deferred | n/a |
| Red Hat Integration Camel Quarkus 1 | undertow | Fix deferred | n/a |
| Red Hat Integration Service Registry | undertow | Not affected | n/a |
| Red Hat JBoss Data Grid 7 | undertow | Out of support scope | n/a |
| Red Hat JBoss Fuse 6 | undertow | Out of support scope | n/a |
| Red Hat OpenStack Platform 13 (Queens) | undertow | Out of support scope | n/a |
| Red Hat Process Automation 7 | undertow | Not affected | n/a |
| Red Hat build of Quarkus | quarkus-http | Not affected | n/a |
| Red Hat build of Quarkus | undertow | Not affected | n/a |
| Red Hat support for Spring Boot | undertow | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- https://access.redhat.com/security/cve/CVE-2022-2764 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2117506 Issue TrackingVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-35006 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-2764
- https://security.netapp.com/advisory/ntap-20221014-0006/ Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-2764
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-2764 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2117506 | Issue TrackingVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-35006 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-2764 | ||
| https://security.netapp.com/advisory/ntap-20221014-0006/ | Third Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-2764 |
Change history (0)
No recorded changes yet.