Undertow Missing Release of Memory after Effective Lifetime vulnerability
Moderate severity
GitHub Reviewed
Published
Jul 9, 2024
to the GitHub Advisory Database
•
Updated Nov 4, 2024
Package
Affected versions
>= 2.3.0.Alpha1, < 2.3.15.Final
< 2.2.34.Final
Patched versions
2.3.15.Final
2.2.34.Final
Description
Published by the National Vulnerability Database
Jul 8, 2024
Published to the GitHub Advisory Database
Jul 9, 2024
Reviewed
Jul 9, 2024
Last updated
Nov 4, 2024
A vulnerability was found in Undertow. This issue requires enabling the learning-push handler in the server's config, which is disabled by default, leaving the maxAge config in the handler unconfigured. The default is -1, which makes the handler vulnerable. If someone overwrites that config, the server is not subject to the attack. The attacker needs to be able to reach the server with a normal HTTP request.
References