Red Hat JBoss Enterprise Application Platform (EAP) 7, when operating as a reverse-proxy with default buffer sizes, allows remote attackers to cause a denial of service (CPU and disk consumption) via a long URL.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| io.undertow:undertow-core(Maven) | 1.4.0 | 1.4.3.Final | N/A |
| io.undertow:undertow-core(Maven) | 0 | 1.3.25.Final | N/A |
CVSS Metrics