Skip to content
VulniPulse
Highest advisory severityHigh 1 vendor · 1 advisory

CVE-2024-3884

CVE-2024-3884: 1 tracked advisory record across Red Hat. Compare source-reported impact, fixes and remediation.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityHigh7.5

    High [CVE-2024-3884] outofmemory when parsing form data encoding with application/x-www-form-urlencoded

    CVE-2024-3884Source published Source updated

    A flaw was found in Undertow that can cause remote denial of service attacks. When the server uses the FormEncodedDataDefinition.doParse(StreamSourceChannel) method to parse large form data encoding with application/x-www-form-urlencoded, the method will cause an OutOfMemory issue. This flaw allows unauthorized users to cause a remote denial of service (DoS) attack. Red Hat rates this as a Moderate impact since this requires the use of a specific form method by the server that must be externally available and the input is not sanitized by the given servlet or class implementing its use. Weakness: CWE-20.

    Affected products in this advisory
    • Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7
    • Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7
    • Red Hat JBoss Enterprise Application Platform 7.4.24
    • Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7

    10 more entries in the full advisory.

    Source-reported affected versions
    Affected-version details not available in this record.
    Source-reported fixed versions
    • eap7-undertow-0:1.4.18-19.SP17_redhat_00001.1.ep7.el7
    • eap7-wildfly-0:7.1.14-4.GA_redhat_00003.1.ep7.el7
    • eap7-undertow-0:2.0.41-7.SP8_redhat_00001.1.el7eap
    • eap7-wildfly-0:7.3.17-5.GA_redhat_00006.1.el7eap

    46 more entries in the full advisory.

    Mitigation guidance
    • It is possible to mitigate the vulnerability by performing an upper-level verification to ensure the content size sent server side is within the allowed parameters.

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery