CVE-2024-3653 - CVE House
Back to Database
Status published Medium CVE-2024-3653

Undertow: learningpushhandler can lead to remote memory dos attacks

Vulnerability Description

A vulnerability was found in Undertow. This issue requires enabling the learning-push handler in the server's config, which is disabled by default, leaving the maxAge config in the handler unconfigured. The default is -1, which makes the handler vulnerable. If someone overwrites that config, the server is not subject to the attack. The attacker needs to be able to reach the server with a normal HTTP request.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-3653

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Red Hat would like to thank Keke Lian, Haoran Zhao, and Yongheng Liu (Secsys Lab of Fudan University) for reporting this issue.

Affected Vendor

Affected Software

Red Hat build of Quarkus 3.8.6.redhat, Red Hat JBoss Enterprise Application Platform 7, Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8, Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9, Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7, Red Hat JBoss Enterprise Application Platform 8, OpenShift Serverless, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apache Camel for Spring Boot 4, Red Hat build of Apache Camel - HawtIO 4, Red Hat build of Apicurio Registry 2, Red Hat Build of Keycloak, Red Hat build of OptaPlanner 8, Red Hat build of Quarkus, Red Hat Data Grid 8, Red Hat Fuse 7, Red Hat Integration Camel K 1, Red Hat Integration Camel Quarkus 2, Red Hat JBoss Data Grid 7, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat JBoss Fuse Service Works 6, Red Hat Process Automation 7, Red Hat Single Sign-On 7, streams for Apache Kafka
Vulnerable Versions:
0, 5.2.4.redhat-00001, 0:2.2.33-1.SP1_redhat_00001.1.el8eap, 0:2.2.33-1.SP1_redhat_00001.1.el9eap, 0:2.2.33-1.SP1_redhat_00001.1.el7eap

Timeline

Official Publish: July 8th, 2024
Last Modified: November 7th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Weaknesses (CWE)