Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:12225
HistoryJan 15, 2019 - 9:14 a.m.

Denial Of Service (DoS)

2019-01-1509:14:29
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.039 Low

EPSS

Percentile

92.0%

undertow-core is vulnerable to denial of service attacks. The vulnerability exists when a GET request with very long URL (about 1900 characters) which exceeds the default buffer sizes is sent to the proxy server, it consumes 100% CPU and fills the disk space by generating logs very fast with an infinite loop.

0.039 Low

EPSS

Percentile

92.0%