| Title | 複数のレッドハット製品における脆弱性 |
|---|---|
| Summary | Undertow、Red Hat OpenShift Container Platform、Red Hat OpenShift Container Platform for ibm linuxone 等複数のレッドハット製品には、不特定の脆弱性が存在します。 |
| Possible impacts | サービス運用妨害 (DoS) 状態にされる可能性があります。 |
| Solution | ベンダアドバイザリまたはパッチ情報が公開されています。参考情報を参照して適切な対策を実施してください。 |
| Publication Date | Sept. 27, 2023, midnight |
| Registration Date | Dec. 20, 2023, 12:08 p.m. |
| Last Update | Dec. 20, 2023, 12:08 p.m. |
| CVSS3.0 : 重要 | |
| Score | 7.5 |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| レッドハット |
| JBoss Enterprise Application Platform 7.4 |
| JBoss Enterprise Application Platform Text-Only Advisories |
| openshift container platform for power 4.10 |
| openshift container platform for power 4.9 |
| Red Hat OpenShift Container Platform 4.11 |
| Red Hat OpenShift Container Platform 4.12 |
| Red Hat OpenShift Container Platform for ibm linuxone 4.10 |
| Red Hat OpenShift Container Platform for ibm linuxone 4.9 |
| Single Sign-On |
| Single Sign-On 7.6 |
| Undertow 2.2.24 未満 |
| No | Changed Details | Date of change |
|---|---|---|
| 1 | [2023年12月20日] 掲載 |
Dec. 20, 2023, 12:08 p.m. |
| Summary | A flaw was found in undertow. Servlets annotated with @MultipartConfig may cause an OutOfMemoryError due to large multipart content. This may allow unauthorized users to cause remote Denial of Service (DoS) attack. If the server uses fileSizeThreshold to limit the file size, it's possible to bypass the limit by setting the file name in the request to null. |
|---|---|
| Publication Date | Sept. 28, 2023, 12:18 a.m. |
| Registration Date | Sept. 28, 2023, 10:01 a.m. |
| Last Update | Nov. 21, 2024, 5:16 p.m. |
| Configuration1 | or higher | or less | more than | less than | |
| cpe:2.3:a:redhat:undertow:*:*:*:*:*:*:*:* | 2.2.24 | ||||
| Configuration2 | or higher | or less | more than | less than | |
| cpe:2.3:a:redhat:openshift_container_platform:4.11:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:redhat:openshift_container_platform:4.12:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:redhat:openshift_container_platform_for_ibm_linuxone:4.9:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:redhat:openshift_container_platform_for_ibm_linuxone:4.10:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:redhat:openshift_container_platform_for_power:4.9:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:redhat:openshift_container_platform_for_power:4.10:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* | ||||
| Configuration3 | or higher | or less | more than | less than | |
| cpe:2.3:a:redhat:single_sign-on:-:*:*:*:text-only:*:*:* | |||||
| cpe:2.3:a:redhat:jboss_enterprise_application_platform_text-only_advisories:-:*:*:*:*:*:*:* | |||||
| Configuration4 | or higher | or less | more than | less than | |
| cpe:2.3:a:redhat:single_sign-on:7.6:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* | ||||
| 2 | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* | ||||
| 3 | cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* | ||||
| Configuration5 | or higher | or less | more than | less than | |
| cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.4:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* | ||||
| 2 | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* | ||||
| 3 | cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* | ||||