Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

[UNDERTOW-2239] CVE-2023-1108 At SslConduit.wrapAndFlip, do not attem… #1453

Merged
merged 1 commit into from
Mar 25, 2023

Conversation

fl4via
Copy link
Member

@fl4via fl4via commented Mar 25, 2023

…pt to wrap if engine.isInboundDone()

Jira: https://issues.redhat.com/browse/UNDERTOW-2239

…pt to wrap if engine.isInboundDone()

Signed-off-by: Flavia Rainone <frainone@redhat.com>
@fl4via fl4via added bug fix Contains bug fix(es) next release This PR will be merged before next release or has already been merged (for payload double check) labels Mar 25, 2023
@fl4via fl4via merged commit 1b76306 into undertow-io:master Mar 25, 2023
@fl4via fl4via deleted the UNDERTOW-2239 branch March 25, 2023 18:07
@fl4via fl4via removed the next release This PR will be merged before next release or has already been merged (for payload double check) label Apr 4, 2023
@marcospds
Copy link

Good afternoon @fl4via, how are you? Could you help me with a question? From what I've seen, this issue already had backport bug fixes in pull request #1457 and was released in version 2.2.24.Final. However, this vulnerability CVE-2023-1108 is still listed as unresolved in versions < 2.3.5.Final, as reported four days ago. Is that correct?

aldiyen added a commit to paytronix/undertow that referenced this pull request Mar 29, 2024
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
bug fix Contains bug fix(es)
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants