CVE-2018-1114

CVSS v3.0 6.5 (Medium)
65% Progress
CVSS v2.0 4 (Medium)
40% Progress
EPSS 0.38 % (73th)
0.38% Progress
Affected Products 3
Advisories 1

It was found that URLResource.getLastModified() in Undertow closes the file descriptors only when they are finalized which can cause file descriptors to exhaust. This leads to a file handler leak.

Weaknesses
CWE-400
Uncontrolled Resource Consumption
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2018-09-11 15:29:00
(6 years ago)
Updated Date
2019-10-09 23:38:07
(5 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Redhat Undertow cpe:2.3:a:redhat:undertow:-
  Redhat Virtualization 4.0 cpe:2.3:a:redhat:virtualization:4.0
  Redhat Virtualization 4.2 cpe:2.3:a:redhat:virtualization:4.2
  Redhat Virtualization Host 4.0 cpe:2.3:a:redhat:virtualization_host:4.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...