SB20231212125 - Allocation of resources without limits or throttling in Undertow 



SB20231212125 - Allocation of resources without limits or throttling in Undertow

Published: December 12, 2023 Updated: July 3, 2025

Security Bulletin ID SB20231212125
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2023-5379)

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability occurs when an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error state by mod_cluster in httpd, causing JBoss EAP to close the TCP connection without returning an AJP response. This happens because mod_proxy_cluster marks the JBoss EAP instance as an error worker when the TCP connection is closed from the backend after sending the AJP request without receiving an AJP response, and stops forwarding. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Remediation

Install update from vendor's website.