A flaw was discovered in Undertow in versions before Undertow 2.1.1.Final where certain requests to the "Expect: 100-continue" header may cause an out of memory error. This flaw may potentially lead to a denial of service.
References
Link | Resource |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1803241 | Issue Tracking Vendor Advisory |
https://security.netapp.com/advisory/ntap-20220210-0014/ | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Information
Published : 2020-06-10 13:15
Updated : 2022-02-22 02:02
NVD link : CVE-2020-10705
Mitre link : CVE-2020-10705
JSON object : View
CWE
CWE-770
Allocation of Resources Without Limits or Throttling
Products Affected
redhat
- undertow
- enterprise_linux
- jboss_enterprise_application_platform
- openshift_application_runtimes
netapp
- oncommand_insight