Back to search
CVE-2018-1114
Published: Sep 11, 2018
Modified: Aug 5, 2024
PUBLISHED
CVSS v3.0
6.5
MEDIUM
Description
It was found that URLResource.getLastModified() in Undertow closes the file descriptors only when they are finalized which can cause file descriptors to exhaust. This leads to a file handler leak.
| Vendor | Product | Versions |
|---|---|---|
Red Hat | undertow | affected n/a |
Weaknesses (CWE)
CVSS v3.0 Details
CVSS v3.0 Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
References
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1114
x_refsource_CONFIRM
RHSA-2018:2669
vendor-advisory
x_refsource_REDHAT
RHSA-2018:2643
vendor-advisory
x_refsource_REDHAT
https://issues.jboss.org/browse/UNDERTOW-1338
x_refsource_MISC
https://bugs.openjdk.java.net/browse/JDK-6956385
x_refsource_MISC
RHSA-2019:0877
vendor-advisory
x_refsource_REDHAT
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now