VulnerabilityModified
CVE-2018-1114
This leads to a file handler leak.
MEDIUM 6.5EPSS 2.33%
Does this matter?
Lower severity and a low EPSS score (2.33%). Track it; it rarely justifies an emergency change on its own.
Description
It was found that URLResource.getLastModified() in Undertow closes the file descriptors only when they are finalized which can cause file descriptors to exhaust. This leads to a file handler leak.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 2.33% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-400
- Affected
- redhat/undertow · redhat/virtualization · redhat/virtualization host
- Source
- secalert@redhat.com
References
- https://access.redhat.com/errata/RHSA-2018:2643Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2669Vendor Advisory
- https://access.redhat.com/errata/RHSA-2019:0877Vendor Advisory
- https://bugs.openjdk.java.net/browse/JDK-6956385Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1114Issue Tracking, Vendor Advisory
- https://issues.jboss.org/browse/UNDERTOW-1338Issue Tracking, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2643Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2669Vendor Advisory
- https://access.redhat.com/errata/RHSA-2019:0877Vendor Advisory
- https://bugs.openjdk.java.net/browse/JDK-6956385Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1114Issue Tracking, Vendor Advisory
- https://issues.jboss.org/browse/UNDERTOW-1338Issue Tracking, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.