Bug 2276410 (CVE-2024-4027)

Summary: CVE-2024-4027 undertow: OutOfMemoryError in HttpServletRequestImpl.getParameterNames() can cause remote DoS attacks
Product: [Other] Security Response Reporter: Patrick Del Bello <pdelbell>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: abrianik, adupliak, anstephe, ant, anujha, aschwart, asoldano, aszczucz, aucunnin, avibelli, bbaranow, bgeorges, bmaxwell, boliveir, brian.stansberry, bstansbe, cescoffi, chazlett, chfoley, clement.escoffier, cmiranda, dandread, darran.lofthouse, dhanak, dkreling, dlofthou, dosoudil, drichtar, drosa, dsimansk, eric.wittmann, fjansen, fmariani, fmongiar, ggrzybek, gmalinko, gsmet, gsuckevi, ibek, istudens, ivassile, iweiss, janstey, jkoops, jmartisk, jnethert, jpoth, jraez, jrokos, jwon, kingland, kverlaen, lthon, manderse, matzew, max.andersen, mcarlett, mnovotny, mosmerov, mposolda, msochure, mstefank, mstoklus, msvehla, mulliken, nipatil, nwallace, olubyans, pantinor, parichar, pberan, pcongius, pdelbell, pdrozd, peholase, pesilva, pgallagh, pierdipi, pjindal, pmackay, probinso, pskopek, rguimara, rhuss, rkubis, rmartinc, rowaters, rruss, rstancel, rstepani, rsvoboda, saroy, sausingh, sbiarozk, sdouglas, security-response-team, smaestri, ssilvert, sthorger, swoodman, tasato, tcunning, thjenkin, tom.jenkinson, tqvarnst, vdosoudi, vmuzikar, yfang
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in Undertow. Servlets using a method that calls HttpServletRequestImpl.getParameterNames() can cause an OutOfMemoryError when the client sends a request with large parameter names. This issue can be exploited by an unauthorized user to cause a remote denial-of-service (DoS) attack.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2236546    

Description Patrick Del Bello 2024-04-22 13:12:56 UTC
There exists a security vulnerability in Undertow that can cause remote DoS attacks. Servlets using method that calls HttpServletRequestImpl.getParameterNames() will cause OutOfMemoryError when the client sends a request with huge parameter names. This vulnerability can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack.