The vendor explicitly identifies these products as affected by this CVE.
- undertow as a component of Red Hat Fuse 7
- undertow as a component of Red Hat JBoss Data Grid 7
- undertow as a component of Red Hat JBoss Enterprise Application Platform 7
- undertow as a component of Red Hat JBoss Fuse Service Works 6
- undertow as a component of Red Hat Process Automation 7
- Summary
- A flaw was found in Undertow that can cause remote denial of service attacks. When the server uses the FormEncodedDataDefinition.doParse(StreamSourceChannel) method to parse large form data encoding with application/x-www-form-urlencoded, the method will cause an OutOfMemory issue. This flaw allows unauthorized users to cause a remote denial of service (DoS) attack.
- Remediation
- Before applying this update, ensure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database settings. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
