CVE-2023-1108
14.09.2023, 15:15
A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.
| Vendor | Product | Version |
|---|---|---|
| redhat | build_of_quarkus | - |
| redhat | decision_manager | 7.0 |
| redhat | fuse | 1.0.0 |
| redhat | integration_camel_k | - |
| redhat | integration_service_registry | - |
| redhat | jboss_enterprise_application_platform | - |
| redhat | jboss_enterprise_application_platform_expansion_pack | - |
| redhat | openshift_application_runtimes | - |
| redhat | openstack_platform | 13.0 |
| redhat | process_automation | 7.0 |
| redhat | single_sign-on | - |
| redhat | undertow | 𝑥 < 2.2.24 |
| redhat | undertow | 2.3.0 ≤ 𝑥 < 2.3.5 |
| redhat | openshift_container_platform | 4.11 |
| redhat | openshift_container_platform | 4.12 |
| redhat | openshift_container_platform_for_linuxone | 4.9 |
| redhat | openshift_container_platform_for_linuxone | 4.10 |
| redhat | openshift_container_platform_for_power | 4.9 |
| redhat | openshift_container_platform_for_power | 4.10 |
| redhat | jboss_enterprise_application_platform | 7.4 |
| redhat | single_sign-on | 7.6 |
| netapp | oncommand_workflow_automation | - |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration
References