CVE-2016-7046
MEDIUM5.9EPSS 4.1%Undertow Uncaught Exception vulnerability
發布日:2022/5/17修改日:2026/4/28
描述
Red Hat JBoss Enterprise Application Platform (EAP) 7, when operating as a reverse-proxy with default buffer sizes, allows remote attackers to cause a denial of service (CPU and disk consumption) via a long URL.
受影響套件(2)
- Debian/undertowfrom 0, < 1.4.3-1
- Maven/io.undertow:undertow-core>= 1.4.0, < 1.4.3.Final
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.9 | CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
參考連結(6)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2016-7046
- PATCHhttps://github.com/undertow-io/undertow
- WEBhttps://bugzilla.redhat.com/show_bug.cgi?id=1376646
- WEBhttps://github.com/undertow-io/undertow/commit/c518b5a1784061d807efedcef0a03fcd35a53de2
- WEBhttps://issues.redhat.com/browse/UNDERTOW-835
- WEBhttps://security-tracker.debian.org/tracker/CVE-2016-7046