Total vulnerabilities in the database
A flaw was found in Undertow. For an AJP 400 response, EAP 7 is improperly sending two response packets, and those packets have the reuse flag set even though JBoss EAP closes the connection. A failure occurs when the connection is reused after a 400 by CPING since it reads in the second SEND_HEADERS response packet instead of a CPONG.
Software | From | Fixed in |
---|---|---|
redhat / single_sign-on | 7.0 | 7.0.x |
redhat / undertow | 2.3.0-alpha1 | 2.3.0-alpha1.x |
redhat / undertow | 2.2.19-sp1 | 2.2.19-sp1.x |
redhat / undertow | 2.2.19 | 2.2.19.x |
redhat / undertow | 2.2.17 | 2.2.17.x |
redhat / undertow | 2.2.17-sp1 | 2.2.17-sp1.x |
redhat / undertow | 2.2.17-sp2 | 2.2.17-sp2.x |
redhat / undertow | - | 2.2.17 |