← 戻る
Webアプリケーション
CVE-2024-5971 high CVSS 7.5

A vulnerability was found in Undertow, where the chunked response hangs after the body was flushed. The response headers and body were sent but the client would continue waiting as Undertow does not s...

概要

A vulnerability was found in Undertow, where the chunked response hangs after the body was flushed. The response headers and body were sent but the client would continue waiting as Undertow does not send the expected 0\r\n termination of the chunked response. This results in uncontrolled resource co...

AI要約 openai / gpt-4o

Undertowで、チャンク応答がフラッシュされた後にハングする脆弱性が発見されました。この問題は、Java 17 TLSv1.3シナリオでのみ発生します。この脆弱性により、サーバー側でのリソース消費が制御できなくなり、サービス拒否攻撃を受ける可能性があります。
❓ 何が問題か
Undertowにおいて、チャンクされた応答がフラッシュ後にハングする脆弱性。
📍 影響範囲
Java 17 TLSv1.3使用時のUndertow。
🔥 重要度
この脆弱性により、サービス拒否攻撃が可能となる。
🔧 修正方法
Undertowのアップデートを待ち、最新のパッチを適用すること。
🛡️ 暫定回避
情報なし
🔍 検知方法
Java 17 TLSv1.3を使用しているかを確認し、異常なリソース消費がないか監視する。

参照URL

🍪 Cookie について

当サイトはログイン状態の保持・言語設定・サービス改善のために Cookie を使用します。詳細は下記リンクをご確認ください。

詳細 →