Undertow: infinite loop in sslconduit during close
Published Sep 14, 2023
7.5
HIGHCVSS 3.1
EPSS 1.77%
Description
A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.
Affected products
- Vendor Red Hat Product Red Hat JBoss Enterprise Application Platform Expansion Pack Defaultaffected
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Red Hat | Red Hat Integration Camel K | affected | |
| Red Hat | Red Hat Integration Service Registry | affected | |
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | affected | |
| Red Hat | Red Hat OpenStack Platform 13 (Queens) | affected |
Configuration 1
- n/a
- 7.0
- 1.0.0
- n/a
- n/a
- n/a
- n/a
- n/a
- 13.0
- 7.0
- n/a
- < 2.2.24
- ≥ 2.3.0 · < 2.3.5
Configuration 2
- 4.11
- 4.12
- 4.9
- 4.10
- 4.9
- 4.10
Running on/with
- 8.0
Configuration 3
- 7.4
Running on/with
- 7.0
- 8.0
- 9.0
Configuration 4
- 7.6
Running on/with
- 7.0
- 8.0
- 9.0
Configuration 5
- n/a
No data.
RHEL-8 based Middleware Containers
rh-sso-7/sso76-openshift-rhel8:7.6-24
Fixed · RHSA-2023:3888
RHPAM 7.13.1 async
undertow
Fixed · RHSA-2023:2135
Red Hat Fuse 7.12
undertow
Fixed · RHSA-2023:3954
Red Hat JBoss Enterprise Application Platform 7
n/a
Fixed · RHSA-2023:1516
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-activemq-artemis-0:1.5.5.016-1.redhat_00001.1.ep7.el7
Fixed · RHSA-2025:4226
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-artemis-native-1:1.5.5.016-1.redhat_00001.1.ep7.el7
Fixed · RHSA-2025:4226
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-jboss-xnio-base-0:3.5.11-1.Final_redhat_00001.1.ep7.el7
Fixed · RHSA-2025:4226
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-jsoup-0:1.14.2-1.redhat_00002.1.ep7.el7
Fixed · RHSA-2025:4226
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-undertow-0:1.4.18-14.SP13_redhat_00001.1.ep7.el7
Fixed · RHSA-2025:4226
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-wildfly-0:7.1.10-2.GA_redhat_00002.1.ep7.el7
Fixed · RHSA-2025:4226
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-woodstox-core-0:5.0.3-2.redhat_00002.1.ep7.el7
Fixed · RHSA-2025:4226
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
eap7-xml-security-0:2.0.10-2.redhat_00002.1.ep7.el7
Fixed · RHSA-2025:4226
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-jackson-annotations-0:2.10.4-3.redhat_00006.1.el7eap
Fixed · RHSA-2025:9583
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-jackson-core-0:2.10.4-3.redhat_00006.1.el7eap
Fixed · RHSA-2025:9583
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-jackson-databind-0:2.10.4-5.redhat_00006.1.el7eap
Fixed · RHSA-2025:9583
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-jackson-jaxrs-providers-0:2.10.4-3.redhat_00006.1.el7eap
Fixed · RHSA-2025:9583
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-jackson-modules-base-0:2.10.4-5.redhat_00006.1.el7eap
Fixed · RHSA-2025:9583
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-jackson-modules-java8-0:2.10.4-2.redhat_00006.1.el7eap
Fixed · RHSA-2025:9583
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-jboss-server-migration-0:1.7.2-16.Final_redhat_00017.1.el7eap
Fixed · RHSA-2025:9583
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-netty-0:4.1.63-5.Final_redhat_00003.1.el7eap
Fixed · RHSA-2025:9583
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-undertow-0:2.0.41-4.SP5_redhat_00001.1.el7eap
Fixed · RHSA-2025:9583
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-wildfly-0:7.3.14-3.GA_redhat_00002.1.el7eap
Fixed · RHSA-2025:9583
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
eap7-wildfly-elytron-0:1.10.17-1.Final_redhat_00001.1.el7eap
Fixed · RHSA-2025:9583
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8
eap7-undertow-0:2.2.22-1.SP3_redhat_00002.1.el8eap
Fixed · RHSA-2023:1185
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8
eap7-undertow-0:2.2.23-1.SP2_redhat_00001.1.el8eap
Fixed · RHSA-2023:1513
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8
eap7-undertow-jastow-0:2.0.14-1.Final_redhat_00001.1.el8eap
Fixed · RHSA-2023:1513
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8
eap7-wildfly-0:7.4.9-6.GA_redhat_00004.1.el8eap
Fixed · RHSA-2023:1185
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9
eap7-undertow-0:2.2.22-1.SP3_redhat_00002.1.el9eap
Fixed · RHSA-2023:1185
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9
eap7-undertow-0:2.2.23-1.SP2_redhat_00001.1.el9eap
Fixed · RHSA-2023:1514
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9
eap7-undertow-jastow-0:2.0.14-1.Final_redhat_00001.1.el9eap
Fixed · RHSA-2023:1514
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9
eap7-wildfly-0:7.4.9-6.GA_redhat_00004.1.el9eap
Fixed · RHSA-2023:1185
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7
eap7-undertow-0:2.2.22-1.SP3_redhat_00002.1.el7eap
Fixed · RHSA-2023:1185
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7
eap7-undertow-0:2.2.23-1.SP2_redhat_00001.1.el7eap
Fixed · RHSA-2023:1512
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7
eap7-undertow-jastow-0:2.0.14-1.Final_redhat_00001.1.el7eap
Fixed · RHSA-2023:1512
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7
eap7-wildfly-0:7.4.9-6.GA_redhat_00004.1.el7eap
Fixed · RHSA-2023:1185
Red Hat JBoss Enterprise Application Platform 7.4.9
io.undertow/undertow-core:2.2.22.SP3-redhat-00001
Fixed · RHSA-2023:1184
Red Hat Single Sign-On 7
undertow
Fixed · RHSA-2023:3892
Red Hat Single Sign-On 7.6 for RHEL 7
rh-sso7-keycloak-0:18.0.8-1.redhat_00001.1.el7sso
Fixed · RHSA-2023:3883
Red Hat Single Sign-On 7.6 for RHEL 8
rh-sso7-keycloak-0:18.0.8-1.redhat_00001.1.el8sso
Fixed · RHSA-2023:3884
Red Hat Single Sign-On 7.6 for RHEL 9
rh-sso7-keycloak-0:18.0.8-1.redhat_00001.1.el9sso
Fixed · RHSA-2023:3885
Red Hat support for Spring Boot 2.7.13
undertow
Fixed · RHSA-2023:4612
Red Hat Data Grid 8
undertow
Not affected
Red Hat Integration Camel K 1
undertow
Affected
Red Hat Integration Camel Quarkus 1
undertow
Not affected
Red Hat JBoss Data Grid 7
undertow
Out of support scope
Red Hat JBoss Enterprise Application Platform Expansion Pack
undertow
Affected
Red Hat JBoss Fuse 6
undertow
Out of support scope
Red Hat OpenStack Platform 13 (Queens)
undertow
Affected
Red Hat build of Apicurio Registry 2
undertow
Affected
Red Hat build of Quarkus
quarkus-undertow
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| RHEL-8 based Middleware Containers | rh-sso-7/sso76-openshift-rhel8:7.6-24 | Fixed | RHSA-2023:3888 |
| RHPAM 7.13.1 async | undertow | Fixed | RHSA-2023:2135 |
| Red Hat Fuse 7.12 | undertow | Fixed | RHSA-2023:3954 |
| Red Hat JBoss Enterprise Application Platform 7 | n/a | Fixed | RHSA-2023:1516 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-activemq-artemis-0:1.5.5.016-1.redhat_00001.1.ep7.el7 | Fixed | RHSA-2025:4226 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-artemis-native-1:1.5.5.016-1.redhat_00001.1.ep7.el7 | Fixed | RHSA-2025:4226 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-jboss-xnio-base-0:3.5.11-1.Final_redhat_00001.1.ep7.el7 | Fixed | RHSA-2025:4226 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-jsoup-0:1.14.2-1.redhat_00002.1.ep7.el7 | Fixed | RHSA-2025:4226 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-undertow-0:1.4.18-14.SP13_redhat_00001.1.ep7.el7 | Fixed | RHSA-2025:4226 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-wildfly-0:7.1.10-2.GA_redhat_00002.1.ep7.el7 | Fixed | RHSA-2025:4226 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-woodstox-core-0:5.0.3-2.redhat_00002.1.ep7.el7 | Fixed | RHSA-2025:4226 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-xml-security-0:2.0.10-2.redhat_00002.1.ep7.el7 | Fixed | RHSA-2025:4226 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-jackson-annotations-0:2.10.4-3.redhat_00006.1.el7eap | Fixed | RHSA-2025:9583 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-jackson-core-0:2.10.4-3.redhat_00006.1.el7eap | Fixed | RHSA-2025:9583 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-jackson-databind-0:2.10.4-5.redhat_00006.1.el7eap | Fixed | RHSA-2025:9583 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-jackson-jaxrs-providers-0:2.10.4-3.redhat_00006.1.el7eap | Fixed | RHSA-2025:9583 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-jackson-modules-base-0:2.10.4-5.redhat_00006.1.el7eap | Fixed | RHSA-2025:9583 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-jackson-modules-java8-0:2.10.4-2.redhat_00006.1.el7eap | Fixed | RHSA-2025:9583 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-jboss-server-migration-0:1.7.2-16.Final_redhat_00017.1.el7eap | Fixed | RHSA-2025:9583 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-netty-0:4.1.63-5.Final_redhat_00003.1.el7eap | Fixed | RHSA-2025:9583 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-undertow-0:2.0.41-4.SP5_redhat_00001.1.el7eap | Fixed | RHSA-2025:9583 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-wildfly-0:7.3.14-3.GA_redhat_00002.1.el7eap | Fixed | RHSA-2025:9583 |
| Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 | eap7-wildfly-elytron-0:1.10.17-1.Final_redhat_00001.1.el7eap | Fixed | RHSA-2025:9583 |
| Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 | eap7-undertow-0:2.2.22-1.SP3_redhat_00002.1.el8eap | Fixed | RHSA-2023:1185 |
| Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 | eap7-undertow-0:2.2.23-1.SP2_redhat_00001.1.el8eap | Fixed | RHSA-2023:1513 |
| Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 | eap7-undertow-jastow-0:2.0.14-1.Final_redhat_00001.1.el8eap | Fixed | RHSA-2023:1513 |
| Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 | eap7-wildfly-0:7.4.9-6.GA_redhat_00004.1.el8eap | Fixed | RHSA-2023:1185 |
| Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 | eap7-undertow-0:2.2.22-1.SP3_redhat_00002.1.el9eap | Fixed | RHSA-2023:1185 |
| Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 | eap7-undertow-0:2.2.23-1.SP2_redhat_00001.1.el9eap | Fixed | RHSA-2023:1514 |
| Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 | eap7-undertow-jastow-0:2.0.14-1.Final_redhat_00001.1.el9eap | Fixed | RHSA-2023:1514 |
| Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 | eap7-wildfly-0:7.4.9-6.GA_redhat_00004.1.el9eap | Fixed | RHSA-2023:1185 |
| Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 | eap7-undertow-0:2.2.22-1.SP3_redhat_00002.1.el7eap | Fixed | RHSA-2023:1185 |
| Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 | eap7-undertow-0:2.2.23-1.SP2_redhat_00001.1.el7eap | Fixed | RHSA-2023:1512 |
| Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 | eap7-undertow-jastow-0:2.0.14-1.Final_redhat_00001.1.el7eap | Fixed | RHSA-2023:1512 |
| Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 | eap7-wildfly-0:7.4.9-6.GA_redhat_00004.1.el7eap | Fixed | RHSA-2023:1185 |
| Red Hat JBoss Enterprise Application Platform 7.4.9 | io.undertow/undertow-core:2.2.22.SP3-redhat-00001 | Fixed | RHSA-2023:1184 |
| Red Hat Single Sign-On 7 | undertow | Fixed | RHSA-2023:3892 |
| Red Hat Single Sign-On 7.6 for RHEL 7 | rh-sso7-keycloak-0:18.0.8-1.redhat_00001.1.el7sso | Fixed | RHSA-2023:3883 |
| Red Hat Single Sign-On 7.6 for RHEL 8 | rh-sso7-keycloak-0:18.0.8-1.redhat_00001.1.el8sso | Fixed | RHSA-2023:3884 |
| Red Hat Single Sign-On 7.6 for RHEL 9 | rh-sso7-keycloak-0:18.0.8-1.redhat_00001.1.el9sso | Fixed | RHSA-2023:3885 |
| Red Hat support for Spring Boot 2.7.13 | undertow | Fixed | RHSA-2023:4612 |
| Red Hat Data Grid 8 | undertow | Not affected | n/a |
| Red Hat Integration Camel K 1 | undertow | Affected | n/a |
| Red Hat Integration Camel Quarkus 1 | undertow | Not affected | n/a |
| Red Hat JBoss Data Grid 7 | undertow | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | undertow | Affected | n/a |
| Red Hat JBoss Fuse 6 | undertow | Out of support scope | n/a |
| Red Hat OpenStack Platform 13 (Queens) | undertow | Affected | n/a |
| Red Hat build of Apicurio Registry 2 | undertow | Affected | n/a |
| Red Hat build of Quarkus | quarkus-undertow | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (25)
- https://access.redhat.com/errata/RHSA-2023:1184 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2023:1185 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2023:1512 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2023:1513 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2023:1514 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2023:1516 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2023:2135 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2023:3883 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2023:3884 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2023:3885 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2023:3888 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2023:3892 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2023:3954 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2023:4612 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/security/cve/CVE-2023-1108 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2174246 issue-trackingx_refsource_REDHATIssue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-2542 Advisory
- https://github.com/advisories/GHSA-m4mm-pg93-fv78 Advisory
- https://github.com/undertow-io/undertow/commit/1302c8cf4476936802504efe0d36c58dcd954f78
- https://github.com/undertow-io/undertow/commit/1b763064a41a30583b5df9a118898513007a70be
- https://github.com/undertow-io/undertow/commit/ccc053b55f5de9872bc1a4999fd6aa85fc5e146d
- https://github.com/undertow-io/undertow/pull/1457
- https://nvd.nist.gov/vuln/detail/CVE-2023-1108
- https://security.netapp.com/advisory/ntap-20231020-0002 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2023-1108
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub