THREAT OPS › Threat News › [NVD] CVE-2023-5379 (HIGH 7.5) — A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error state by mod_cluster in httpd, causing JBoss EAP to close the TCP connection without returning an AJP response. This happens becau
[NVD] CVE-2023-5379 (HIGH 7.5) — A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error state by mod_cluster in httpd, causing JBoss EAP to close the TCP connection without returning an AJP response. This happens becau
CVE-2023-5379 CVSS: 7.5 HIGH Published: 2023-12-12T22:15:22.410
A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error state by mod_cluster in httpd, causing JBoss EAP to close the TCP connection without returning an AJP response. This happens because mod_proxy_cluster marks the JBoss EAP instance as an
Indicators of compromise
- CVE-2023-5379cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2023-5379