A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of Service by sending crafted requests, leading the server to an OutofMemory error, exhausting the server's memory.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| io.undertow:undertow-core(Maven) | 0 | 2.2.32.Final | N/A |
| io.undertow:undertow-core(Maven) | 2.3.0.Alpha1 | 2.3.13.Final | N/A |
CVSS Metrics