A flaw was found in Undertow when using Remoting as shipped in Red Hat Jboss EAP before version 7.2.4. A memory leak in HttpOpenListener due to holding remote connections indefinitely may lead to denial of service. Versions before undertow 2.0.25.SP1 and jboss-remoting 5.0.14.SP1 are believed to be vulnerable.
| Software | From | Fixed in |
|---|---|---|
| redhat / jboss-remoting | 5.0.14 | 5.0.14.x |
| redhat / jboss-remoting | - | 5.0.14 |
| redhat / undertow | 2.0.25 | 2.0.25.x |
| redhat / undertow | - | 2.0.25 |
| redhat / jboss_enterprise_application_platform | - | 7.2.4 |