Resource management error in Undertow - CVE-2024-4109
Published: December 11, 2024 / Updated: November 24, 2025
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to incorrect handling of HTTP/2 requests when reusing connections, which results in parts of data from previous connection to be included into new responses. A remote attacker can send an HTTP/2 request to the server and gain access to potentially sensitive information.
Affected software
openEuler
undertow
undertow-javadoc
How to mitigate CVE-2024-4109
undertow - update to 1.4.0-8
undertow-javadoc - update to 1.4.0-8