← Retour
CVE-2024-5971
high
CVSS 7.5
A vulnerability was found in Undertow, where the chunked response hangs after the body was flushed. The response headers and body were sent but the client would continue waiting as Undertow does not s...
Résumé
A vulnerability was found in Undertow, where the chunked response hangs after the body was flushed. The response headers and body were sent but the client would continue waiting as Undertow does not send the expected 0\r\n termination of the chunked response. This results in uncontrolled resource co...
Résumé IA openai / gpt-4o
Une vulnérabilité référencée **CVE-2024-5971** a été découverte dans dos.
Risque d'opérations non autorisées ou de divulgation. Score CVSS : 7.5/10.
Action : appliquez le correctif officiel de l'éditeur.
En cas de doute, contactez votre service informatique ou cherchez « dos CVE-2024-5971 » sur le site de l'éditeur.
CVE-2024-5971 (dos) — CWE-674 / CVSS v3 7.5
Vecteur d'attaque : distant (réseau) / non authentifié / sans interaction utilisateur
Plan : 1) Audit SBOM, 2) Mise à jour staging→prod, 3) Surveillance WAF/proxy sur les endpoints affectés, 4) Recherche d'IOC dans les logs.
Réfs : voir GHSA / avis éditeur / version corrigée liés sur cette page.
❓ Quel est le problème
Undertowにおいて、チャンクされた応答がフラッシュ後にハングする脆弱性。
📍 Périmètre concerné
Java 17 TLSv1.3使用時のUndertow。
🔥 Gravité
この脆弱性により、サービス拒否攻撃が可能となる。
🔧 Comment corriger
Undertowのアップデートを待ち、最新のパッチを適用すること。
🛡️ Contournement
情報なし
🔍 Détection
Java 17 TLSv1.3を使用しているかを確認し、異常なリソース消費がないか監視する。
Références
- web af854a3a-2127-422b-91ae-364da2661108
- web af854a3a-2127-422b-91ae-364da2661108
- web [email protected]
- web [email protected]
- web [email protected]
- web [email protected]
- web [email protected]
- web [email protected]
- web af854a3a-2127-422b-91ae-364da2661108
- web af854a3a-2127-422b-91ae-364da2661108
- web af854a3a-2127-422b-91ae-364da2661108