Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-1319
HistoryAug 31, 2022 - 4:15 p.m.

Design/Logic Flaw

2022-08-3116:15:00
PRIOn knowledge base
www.prio-n.com
2
undertow
ajp 400
eap 7
logic flaw
connection closure

8.3 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

71.4%

A flaw was found in Undertow. For an AJP 400 response, EAP 7 is improperly sending two response packets, and those packets have the reuse flag set even though JBoss EAP closes the connection. A failure occurs when the connection is reused after a 400 by CPING since it reads in the second SEND_HEADERS response packet instead of a CPONG.

8.3 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

71.4%