{"id":"CVE-2024-3653","title":"A vulnerability was found in Undertow","summary":"A vulnerability was found in Undertow. This issue requires enabling the learning-push handler in the server's config, which is disabled by default, leaving the maxAge config in the handler unconfigured. The default is -1, which makes the…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","cwe":["CWE-401"],"vendor":"Red Hat","product":"undertow","affected":["undertow <= 2.3.14.Final","io.quarkus.http/quarkus-http-core (all versions)","io.undertow/undertow-core (all versions)","eap7-undertow (all versions)","eap7-undertow (all versions)","eap7-undertow (all versions)","undertow","undertow (all versions)","undertow (all versions)","undertow (all versions)","undertow","undertow","undertow","undertow (all versions)","quarkus-undertow","undertow (all versions)","undertow","undertow (all versions)","undertow (all versions)","undertow","undertow","undertow","undertow","undertow (all versions)","undertow (all versions)"],"published":"2024-07-08","updated":"2026-09-08","sourceUpdated":"2026-09-08T23:17:20.767","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2024-3653","references":[{"url":"https://access.redhat.com/errata/RHSA-2024:4392","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:5143","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:5144","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:5145","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:5147","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:6437","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2024-3653","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2274437","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:4392","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/security/cve/CVE-2024-3653","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2274437","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20240828-0002/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-3653.json"},{"url":"https://www.cve.org/CVERecord?id=CVE-2024-3653"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-3653"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2025-01-09T21:35:33.839379Z"},"epss":0.01866,"epssPercentile":0.78374,"ingestedAt":"2026-08-05T11:47:23.359Z","patched":["jboss_eap_7_4_for_rhel_7_server","jboss_eap_7_4_for_rhel 8","jboss_eap_7_4_for_rhel 9","jboss_enterprise_application_platform 8","jboss_enterprise_application_platform","build_of_quarkus 3.8.6.redhat"],"slug":"CVE-2024-3653","body":"## Overview\n\nA vulnerability was found in Undertow. This issue requires enabling the learning-push handler in the server's config, which is disabled by default, leaving the maxAge config in the handler unconfigured. The default is -1, which makes the handler vulnerable. If someone overwrites that config, the server is not subject to the attack. The attacker needs to be able to reach the server with a normal HTTP request.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **RHSA-2024:5143** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 for RHEL 7 Server · released 2024-08-08 · [advisory](https://access.redhat.com/errata/RHSA-2024:5143)\n- **RHSA-2024:5144** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 for RHEL 8 · released 2024-08-08 · [advisory](https://access.redhat.com/errata/RHSA-2024:5144)\n- **RHSA-2024:5145** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 for RHEL 9 · released 2024-08-08 · [advisory](https://access.redhat.com/errata/RHSA-2024:5145)\n- **RHSA-2024:4392** · Red Hat · fixed in: Red Hat JBoss Enterprise Application Platform 8 · released 2024-07-08 · [advisory](https://access.redhat.com/errata/RHSA-2024:4392)\n- **RHSA-2024:5147** · Red Hat · fixed in: Red Hat JBoss Enterprise Application Platform · released 2024-08-08 · [advisory](https://access.redhat.com/errata/RHSA-2024:5147)\n- **RHSA-2024:6437** · Red Hat · fixed in: Red Hat build of Quarkus 3.8.6.redhat · released 2024-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2024:6437)\n- **Red Hat VEX** · Low · affected: OpenShift Serverless, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Apache Camel for Spring Boot 4, Red Hat build of OptaPlanner 8, Red Hat Data Grid 8, Red Hat Fuse 7, … · no fix planned: Red Hat Fuse 7, Red Hat JBoss Data Grid 7, Red Hat JBoss Fuse Service Works 6, Red Hat Process Automation 7, … · updated 2026-09-08 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-3653.json)","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.2,"likelihood":0.4,"exploitation":0,"ransomware":0},"changes":[]}