CVE-2019-19343

Severity CVSS v4.0:
Pending analysis
Type:
CWE-404 Improper Resource Shutdown or Release
Publication date:
23/03/2021
Last modified:
03/05/2022

Description

A flaw was found in Undertow when using Remoting as shipped in Red Hat Jboss EAP before version 7.2.4. A memory leak in HttpOpenListener due to holding remote connections indefinitely may lead to denial of service. Versions before undertow 2.0.25.SP1 and jboss-remoting 5.0.14.SP1 are believed to be vulnerable.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:jboss-remoting:*:*:*:*:*:*:*:* 5.0.14 (excluding)
cpe:2.3:a:redhat:jboss-remoting:5.0.14:-:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:*:*:*:*:*:*:*:* 7.2.4 (excluding)
cpe:2.3:a:redhat:undertow:*:*:*:*:*:*:*:* 2.0.25 (excluding)
cpe:2.3:a:redhat:undertow:2.0.25:-:*:*:*:*:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vsphere:*:*