Allocation of Resources Without Limits or Throttling Affecting org.wildfly:wildfly-domain-http package, versions [0,]


0.0
medium

Snyk CVSS

    Attack Complexity High
    Privileges Required High
    Availability High

    Threat Intelligence

    EPSS 0.04% (9th percentile)
Expand this section
Red Hat
4.1 medium

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-JAVA-ORGWILDFLY-6808835
  • published 5 May 2024
  • disclosed 2 May 2024
  • credit Unknown

How to fix?

There is no fixed version for org.wildfly:wildfly-domain-http.

Overview

Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling due to the lack of limitation of sockets for the management interface, it may be possible to cause a denial of service hitting the nofile limit as there is no possibility to configure or set a maximum number of connections.

References