CVE-2023-3171

A flaw was found in EAP-7 during deserialization of certain classes, which permits instantiation of HashMap and HashTable with no checks on resources consumed. This issue could allow an attacker to submit malicious requests using these classes, which could eventually exhaust the heap and result in a Denial of Service.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.4:*:*:*:*:*:*:*
OR cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:redhat:jboss_enterprise_application_platform:-:*:*:*:text-only:*:*:*

History

04 Jan 2024, 17:07

Type Values Removed Values Added
Summary
  • (es) Se encontró una falla en EAP-7 durante la deserialización de ciertas clases, lo que permite la creación de instancias de HashMap y HashTable sin verificar los recursos consumidos. Este problema podría permitir que un atacante envíe solicitudes maliciosas utilizando estas clases, lo que eventualmente podría agotar el montón y provocar una denegación de servicio.
CWE CWE-770
References () https://access.redhat.com/errata/RHSA-2023:5484 - () https://access.redhat.com/errata/RHSA-2023:5484 - Vendor Advisory
References () https://access.redhat.com/errata/RHSA-2023:5485 - () https://access.redhat.com/errata/RHSA-2023:5485 - Vendor Advisory
References () https://access.redhat.com/errata/RHSA-2023:5486 - () https://access.redhat.com/errata/RHSA-2023:5486 - Vendor Advisory
References () https://access.redhat.com/errata/RHSA-2023:5488 - () https://access.redhat.com/errata/RHSA-2023:5488 - Vendor Advisory
References () https://access.redhat.com/security/cve/CVE-2023-3171 - () https://access.redhat.com/security/cve/CVE-2023-3171 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2213639 - () https://bugzilla.redhat.com/show_bug.cgi?id=2213639 - Issue Tracking
CPE cpe:2.3:a:redhat:jboss_enterprise_application_platform:-:*:*:*:text-only:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.4:*:*:*:*:*:*:*
First Time Redhat enterprise Linux
Redhat jboss Enterprise Application Platform
Redhat

27 Dec 2023, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-27 16:15

Updated : 2024-01-04 17:07


NVD link : CVE-2023-3171

Mitre link : CVE-2023-3171

CVE.ORG link : CVE-2023-3171


JSON object : View

Products Affected

redhat

  • enterprise_linux
  • jboss_enterprise_application_platform
CWE
CWE-770

Allocation of Resources Without Limits or Throttling

CWE-789

Memory Allocation with Excessive Size Value