CVE-2024-3884
CVE-2024-3884: 1 tracked advisory record across Red Hat. Compare source-reported impact, fixes and remediation.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Red Hat
1 advisory- Advisory severityHigh7.5
High [CVE-2024-3884] outofmemory when parsing form data encoding with application/x-www-form-urlencoded
CVE-2024-3884Source published Source updated
A flaw was found in Undertow that can cause remote denial of service attacks. When the server uses the FormEncodedDataDefinition.doParse(StreamSourceChannel) method to parse large form data encoding with application/x-www-form-urlencoded, the method will cause an OutOfMemory issue. This flaw allows unauthorized users to cause a remote denial of service (DoS) attack. Red Hat rates this as a Moderate impact since this requires the use of a specific form method by the server that must be externally available and the input is not sanitized by the given servlet or class implementing its use. Weakness: CWE-20.
- Affected products in this advisory
- Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
- Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
- Red Hat JBoss Enterprise Application Platform 7.4.24
- Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7
10 more entries in the full advisory.
- Source-reported affected versions
- Affected-version details not available in this record.
- Source-reported fixed versions
- eap7-undertow-0:1.4.18-19.SP17_redhat_00001.1.ep7.el7
- eap7-wildfly-0:7.1.14-4.GA_redhat_00003.1.ep7.el7
- eap7-undertow-0:2.0.41-7.SP8_redhat_00001.1.el7eap
- eap7-wildfly-0:7.3.17-5.GA_redhat_00006.1.el7eap
46 more entries in the full advisory.
- Mitigation guidance
- It is possible to mitigate the vulnerability by performing an upper-level verification to ensure the content size sent server side is within the allowed parameters.
Android app · Google Play
Monitor future Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.