CVE-2018-1114

Related Vulnerabilities: CVE-2018-1114  

It was found that URLResource.getLastModified() in Undertow closes the file descriptors only when they are finalized which can cause file descriptors to exhaust. This leads to a file handler leak.

It was found that URLResource.getLastModified() in Undertow closes the file descriptors only when they are finalized which can cause file descriptors to exhaust. This leads to a file handler leak.

Find out more about CVE-2018-1114 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

CVSS3 Base Score 6.5
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity Impact None
Availability Impact High

Red Hat Security Errata

Platform Errata Release Date
Red Hat Virtualization 4 Management Agent for RHEL 7 Hosts (rhvm-appliance) RHSA-2018:2643 2018-09-04
Red Hat JBoss EAP 7.1 RHSA-2018:2088 2018-06-27
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 Server (eap7-undertow) RHSA-2018:2090 2018-06-27
Red Hat JBoss Fuse 7 RHSA-2018:2669 2018-09-11
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server (eap7-undertow) RHSA-2018:2089 2018-06-27

Affected Packages State

Platform Package State
Red Hat Virtualization 4 eap7-undertow Affected
Red Hat Single Sign-On 7 undertow Affected
Red Hat OpenShift Application Runtimes 1.0 swarm Affected
Red Hat JBoss Fuse 6 undertow Will not fix
Red Hat JBoss EAP 6 jbossweb Not affected
Red Hat JBoss Data Grid 7 undertow Not affected

External References