High severityNVD Advisory· Published Jan 23, 2020· Updated Aug 5, 2024
CVE-2019-14888
CVE-2019-14888
Description
A vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listening on HTTPS. An attacker can target the HTTPS port to carry out a Denial Of Service (DOS) to make the service unavailable on SSL.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
io.undertow:undertow-coreMaven | < 2.0.29.Final | 2.0.29.Final |
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- access.redhat.com/errata/RHSA-2020:0729ghsavendor-advisoryx_refsource_REDHATWEB
- github.com/advisories/GHSA-vjxc-frw4-jmh5ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-14888ghsaADVISORY
- bugzilla.redhat.com/show_bug.cgighsax_refsource_CONFIRMWEB
- security.netapp.com/advisory/ntap-20220211-0001ghsaWEB
- security.netapp.com/advisory/ntap-20220211-0001/mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.