Uploaded image for project: 'Undertow'
  1. Undertow
  2. UNDERTOW-2280

CVE-2023-5379 AJP request which exceed max-header-size cause JBoss EAP to be marked as error status in httpd as a reverse-proxy

XMLWordPrintable

    When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked as an error state by mod_cluster in httpd. The problem is that requests exceeding the max-header-size cause JBoss EAP to close the TCP connection without returning an AJP response.

          flaviarnn Flavia Rainone
          flaviarnn Flavia Rainone
          Bartosz Baranowski, Brad Maxwell, Masafumi Miura, Norito Agetsuma, Parul Sharma, Richard Opalka, Stefano Maestri, Stuart Douglas, Tom Jenkinson
          Votes:
          0 Vote for this issue
          Watchers:
          2 Start watching this issue

            Created:
            Updated:
            Resolved: