Skip to main content
EPSS 2.9%top 14%

CVE-2024-5971: Uncontrolled Recursion in Red Hat Red Hat build of Apache Camel 3.20.7 for Spring Boot

0
High
VulnerabilityCVE-2024-5971cvecve-2024-5971
Published: 07/08/2024 (07/08/2024, 20:51:29 UTC)
Source: CVE Database V5
Vendor/Project: Red Hat
Product: Red Hat build of Apache Camel 3.20.7 for Spring Boot

Description

A vulnerability was found in Undertow, where the chunked response hangs after the body was flushed. The response headers and body were sent but the client would continue waiting as Undertow does not send the expected 0\r\n termination of the chunked response. This results in uncontrolled resource consumption, leaving the server side to a denial of service attack. This happens only with Java 17 TLSv1.3 scenarios.

CVSS v3.1

Score 7.5high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected software

Red Hat

Red Hat build of Apache Camel 3.20.7 for Spring Boot

Red Hat

Red Hat build of Apache Camel 4.4.1 for Spring Boot 3.2

Red Hat

Red Hat build of Apache Camel 4.4.2 for Spring Boot

Red Hat

Red Hat JBoss Enterprise Application Platform

Red Hat

Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8

Red Hat

Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9

Red Hat

Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7

Red Hat

Red Hat JBoss Enterprise Application Platform 8

Red Hat

Red Hat build of Apache Camel for Spring Boot 3

Red Hat

Red Hat build of Apache Camel - HawtIO 4

Red Hat

Red Hat Build of Keycloak

Red Hat

Red Hat build of Quarkus

Red Hat

Red Hat Data Grid 8

Red Hat

Red Hat Fuse 7

Red Hat

Red Hat Integration Camel K 1

Red Hat

Red Hat JBoss Data Grid 7

Red Hat

Red Hat JBoss Enterprise Application Platform 7

Red Hat

Red Hat JBoss Enterprise Application Platform Expansion Pack

Red Hat

Red Hat Process Automation 7

Red Hat

Red Hat Single Sign-On 7

GitHub Actionsmore threats →cve
undertow
pkg:github/undertow
Affected versions
>=0 <2.2.34.Final>=2.3.0.Alpha1 <2.3.15.Final

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/09/2026, 12:57:04 UTC

Technical Analysis

The vulnerability CVE-2024-5971 in Undertow causes the chunked HTTP response to hang after the response body is flushed because the expected 0\r\n termination of the chunked response is not sent. This results in the client waiting indefinitely, leading to uncontrolled resource consumption on the server side and a denial of service condition. The issue specifically occurs in Java 17 TLSv1.3 NewSessionTicket scenarios. Red Hat advisories confirm the vulnerability affects Red Hat JBoss Enterprise Application Platform 8.0 and related Undertow components. Security updates have been issued to fix this problem.

Potential Impact

The vulnerability leads to denial of service by causing the server to consume resources uncontrollably when handling chunked HTTP responses under Java 17 TLSv1.3. There is no impact on confidentiality or integrity, but availability is severely affected. No known exploits in the wild have been reported at this time.

Mitigation Recommendations

Red Hat has released security updates addressing CVE-2024-5971 in Red Hat JBoss Enterprise Application Platform 8.0 and related Undertow components. Users should apply these official patches as per Red Hat's advisories (e.g., RHSA-2024:4392 and RHSA-2024:4884). Before applying updates, ensure all previous errata are applied. Patch status is confirmed as fixed in these advisories. No additional mitigation steps are indicated beyond applying the vendor-provided updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.1
Assigner Short Name
redhat
Date Reserved
2024-06-13T13:50:13.855Z
Cvss Version
3.1
State
PUBLISHED
Vendor Advisory Urls
[{"url":"https://access.redhat.com/errata/RHSA-2024:4392","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2024:4884","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2024:5143","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2024:5144","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2024:5145","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2024:5147","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2024:6508","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2024:6883","vendor":"Red Hat"},{"url":"https://access.redhat.com/security/cve/CVE-2024-5971","vendor":"Red Hat"}]

Threat ID: 68faafd950358b89bd7bfd50

Added to database: 10/23/2025, 22:44:41 UTC

Last enriched: 08/09/2026, 12:57:04 UTC

Last updated: 09/10/2026, 19:46:23 UTC

Views: 497

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses