Lucene search

K
redhatcveRedhat.comRH:CVE-2020-14384
HistorySep 03, 2020 - 10:19 p.m.

CVE-2020-14384

2020-09-0322:19:33
redhat.com
access.redhat.com
17

0.148 Low

EPSS

Percentile

95.8%

A flaw was found in jbossweb. The fix for CVE-2020-13935 was incomplete in JBossWeb, leaving it vulnerable to a denial of service attack when sending multiple requests with invalid payload length in a WebSocket frame. The highest threat from this vulnerability is to system availability.

Mitigation

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update as soon as possible.