Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 Maven

Undertow vulnerable to Uncontrolled Resource Consumption

GHSA-vjxc-frw4-jmh5 · CVE-2019-14888

Published · Modified

Description

A vulnerability was found in the Undertow HTTP server in versions before 2.0.29 when listening on HTTPS. An attacker can target the HTTPS port to carry out a Denial Of Service (DOS) to make the service unavailable on SSL.

Ready to move

Start Securing

Free, no credit card | First findings in minutes