Lucene search

K
cvelistRedhatCVELIST:CVE-2020-14384
HistorySep 09, 2020 - 1:17 p.m.

CVE-2020-14384

2020-09-0913:17:28
CWE-400
redhat
www.cve.org
2

7.6 High

AI Score

Confidence

High

0.148 Low

EPSS

Percentile

95.8%

A flaw was found in JBossWeb in versions before 7.5.31.Final-redhat-3. The fix for CVE-2020-13935 was incomplete in JBossWeb, leaving it vulnerable to a denial of service attack when sending multiple requests with invalid payload length in a WebSocket frame. The highest threat from this vulnerability is to system availability.

CNA Affected

[
  {
    "product": "JBossWeb",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "JBossWeb versions before 7.5.31.Final-redhat-3"
      }
    ]
  }
]