Skip to main content

Threats Tagged 'cve-2024-7885'

View all threats tagged with 'cve-2024-7885'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2024-7885

Threats Tagged 'cve-2024-7885'

Click on any threat for detailed analysis and mitigation recommendations

Red Hat JBoss Enterprise Application Platform 7 is a platform for Java applications based on the WildFly application runtime. This release of Red Hat JBoss Enterprise Application Platform 7.3.15 serves as a replacement for Red Hat JBoss Enterprise Application Platform 7.3.14, and includes bug fixes and enhancements. See the Red Hat JBoss Enterprise Application Platform 7.3.15 Release Notes for information about the most significant bug fixes and enhancements included in this release. Security Fix(es): * commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default (CVE-2025-48734) * undertow: information leakage via HTTP/2 request header reuse [eap-7.3.z] (CVE-2024-4109) * org.hornetq/hornetq-core-client: Arbitrarily overwrite files or access sensitive information [eap-7.3.z] (CVE-2024-51127) * HTTP-2: httpd: CONTINUATION frames DoS [eap-7.3.z] (CVE-2024-27316) * UNDERTOW-2429 undertow: Improper State Management in Proxy Protocol parsing causes information leakage [eap-7.3.z] (CVE-2024-7885) For more details about the security issue(s), including the impact, a CVSS score, acknowledgements, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion

HawtIO 4.1.0 for Red Hat build of Apache Camel 4 GA Release is now available. The purpose of this text-only errata is to inform you about the enhancements that improve your developer experience and ensure the security and stability of your products. * serve-static: Improper Sanitization in serve-static (CVE-2024-43800) * send: Code Execution Vulnerability in Send Library (CVE-2024-43799) * org.springframework/spring-webmvc: Path Traversal Vulnerability in Spring Applications Using RouterFunctions and FileSystemResource (CVE-2024-38816) * org.eclipse.jetty/jetty-server: Jetty ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks (CVE-2024-8184) * quarkus-core: Leak of local configuration properties into Quarkus applications (CVE-2024-2700) * braces: fails to limit the number of characters it can handle (CVE-2024-4068) * undertow: Improper State Management in Proxy Protocol parsing causes information leakage (CVE-2024-7885) * path-to-regexp: Backtracking regular expressions cause ReDoS (CVE-2024-45296) * express: Improper Input Handling in Express Redirects (CVE-2024-43796)

Join the discussion

Red Hat JBoss Enterprise Application Platform 7 is a platform for Java applications based on the WildFly application runtime. This asynchronous patch is a security update for Red Hat JBoss Enterprise Application Platform 7.4. Security Fix(es): * undertow: Improper State Management in Proxy Protocol parsing causes information leakage (CVE-2024-7885) A Red Hat Security Bulletin which addresses further details about this flaw is available in the References section. For more details about the security issue(s), including the impact, a CVSS score, acknowledgements, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion

A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue occurs when the parseProxyProtocolV1 method processes multiple requests on the same HTTP connection. As a result, different requests may share the same StringBuilder instance, potentially leading to information leakage between requests or responses. In some cases, a value from a previous request or response may be erroneously reused, which could lead to unintended data exposure. This issue primarily results in errors and connection termination but creates a risk of data leakage in multi-request environments.

Join the discussion
0

A vulnerability was found in Undertow, where the chunked response hangs after the body was flushed. The response headers and body were sent but the client would continue waiting as Undertow does not send the expected 0\r\n termination of the chunked response. This results in uncontrolled resource consumption, leaving the server side to a denial of service attack. This happens only with Java 17 TLSv1.3 scenarios.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Tag: cve-2024-7885
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses