GHSA-gjjx-gqm4-wcgm
Dashboard / Vulnerabilities / GHSA-gjjx-gqm4-wcgm
Summary: Uncontrolled Resource Consumption in Undertow
Details: It was found that URLResource.getLastModified() in Undertow closes the file descriptors only when they are finalized which can cause file descriptors to exhaust. This leads to a file handler leak.
References: https://nvd.nist.gov/vuln/detail/CVE-2018-1114, https://access.redhat.com/errata/RHSA-2018:2643, https://access.redhat.com/errata/RHSA-2018:2669, https://access.redhat.com/errata/RHSA-2019:0877, https://bugs.openjdk.java.net/browse/JDK-6956385, https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1114, https://issues.jboss.org/browse/UNDERTOW-1338
Affected packages
Package
Name: io.undertow:undertow-core
Purl: pkg:maven/io.undertow/undertow-core
Affected ranges
Type: ECOSYSTEM
Events:
