CVE-2017-2670

Impact:
Moderate
Public Date:
2017-06-07
CWE:
CWE-835
Bugzilla:
1438885: CVE-2017-2670 undertow: IO thread DoS via unclean Websocket closing
It was found that with non-clean TCP close, Websocket server gets into infinite loop on every IO thread, effectively causing DoS.

Find out more about CVE-2017-2670 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

CVSS3 Base Score 7.5
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality None
Integrity Impact None
Availability Impact High

Red Hat Security Errata

Platform Errata Release Date
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 Server (eap7-jboss-ec2-eap) RHSA-2017:3458 2017-12-13
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server (eap7-jboss-ec2-eap) RHSA-2017:3458 2017-12-13
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server RHSA-2017:1411 2017-06-07
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server (eap7-jboss-ec2-eap) RHSA-2017:1412 2017-06-07
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 Server RHSA-2017:3454 2017-12-13
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server RHSA-2017:3455 2017-12-13
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 Server (eap7-jboss-ec2-eap) RHSA-2017:1412 2017-06-07
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 Server RHSA-2017:1410 2017-06-07
Red Hat Single Sign-On 7.2 RHSA-2018:0501 2018-03-13
Red Hat JBoss EAP 7 RHSA-2017:1409 2017-06-07
Red Hat JBoss Data Grid 7.1 RHSA-2017:3244 2017-11-16
Red Hat JBoss EAP 7 RHSA-2017:3456 2017-12-13

Affected Packages State

Platform Package State
Red Hat Single Sign-On 7 wildfly Will not fix
Red Hat JBoss Fuse 7 karaf Will not fix
Red Hat JBoss Fuse 6 karaf Will not fix

Acknowledgements

Red Hat would like to thank Gregory Ramsperger and Ryan Moak for reporting this issue.

Last Modified
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.