Unchecked Return Value in Undertow - CVE-2022-1319
Published: June 7, 2022
Vulnerability identifier: #VU64026
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-1319
CWE-ID: CWE-252
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to EAP 7 improperly sends two response packets, and those packets have the reuse flag set even though JBoss EAP closes the connection. A remote attacker can trigger the vulnerability to perform a denial of service attack.
The vulnerability exists due to EAP 7 improperly sends two response packets, and those packets have the reuse flag set even though JBoss EAP closes the connection. A remote attacker can trigger the vulnerability to perform a denial of service attack.
Affected software
Undertow
JBoss Enterprise Application Platform
Wildfly Core
Oracle Communications Cloud Native Core Network Repository Function
JBoss Enterprise Application Platform
Wildfly Core
Oracle Communications Cloud Native Core Network Repository Function
How to mitigate CVE-2022-1319
Install updates from vendor's website.
Undertow - update to 2.2.14
JBoss Enterprise Application Platform - update to 7.4.5
Wildfly Core - update to 18.1.2
JBoss Enterprise Application Platform - update to 7.4.5
Wildfly Core - update to 18.1.2