A flaw was found in Undertow. For an AJP 400 response,...
High severity
Unreviewed
Published
Sep 1, 2022
to the GitHub Advisory Database
•
Updated Jan 28, 2023
Description
Published by the National Vulnerability Database
Aug 31, 2022
Published to the GitHub Advisory Database
Sep 1, 2022
Last updated
Jan 28, 2023
A flaw was found in Undertow. For an AJP 400 response, EAP 7 is improperly sending two response packets, and those packets have the reuse flag set even though JBoss EAP closes the connection. A failure occurs when the connection is reused after a 400 by CPING since it reads in the second SEND_HEADERS response packet instead of a CPONG.
References