cvedb.io
CVE-2024-1635
HIGH · CVSS 7.5
EPSS exploitation probability: 0%
Published 2024-02-19T22:15:48.647 · Last modified 2026-08-04T08:16:31.250

Summary

A vulnerability was found in Undertow. This vulnerability impacts a server that supports the wildfly-http-client protocol. Whenever a malicious user opens and closes a connection with the HTTP port of the server and then closes the connection immediately, the server will end with both memory and open file limits exhausted at some point, depending on the amount of memory available. At HTTP upgrade to remoting, the WriteTimeoutStreamSinkConduit leaks connections if RemotingConnection is closed by Remoting ServerConnectionOpenListener. Because the remoting connection originates in Undertow as part of the HTTP upgrade, there is an external layer to the remoting connection. This connection is unaware of the outermost layer when closing the connection during the connection opening procedure.

Affected products

netapp — active_iq_unified_manager

Does this affect you?

Add your gear to cvedb and we'll alert you only when netapp ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.