{"id":"CVE-2023-1973","aliases":["GHSA-97cq-f4jm-mv8h"],"url":"https://o3.security/vulnerability/CVE-2023-1973","summary":"Undertow Denial of Service vulnerability","details":"A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of Service by sending crafted requests, leading the server to an OutofMemory error, exhausting the server's memory.","published":"2024-11-07T10:15:05Z","modified":"2025-01-09T04:48:55.235385Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Debian:13","name":"undertow","fixedVersion":"2.3.18-1"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:1674"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:1675"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:1676"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:1677"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:2763"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:2764"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2185662"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2023-1973"},{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2023-1973"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-01-09T04:48:55.235385Z"}}