The vendor explicitly identifies these products as affected by this CVE.
- undertow-core as a component of Red Hat Data Grid 8
- undertow-core as a component of Red Hat Fuse 7
- undertow-core as a component of Red Hat JBoss Enterprise Application Platform 7
- org.jboss.eap-jboss-eap-xp as a component of Red Hat JBoss Enterprise Application Platform Expansion Pack
- undertow-core as a component of Red Hat Process Automation 7
- undertow-core as a component of Red Hat Single Sign-On 7
- Summary
- A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).
- Remediation
- Before applying this update, ensure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database settings. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
