{"id":"CVE-2024-7885","title":"A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests","summary":"A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue occurs when the parseProxyProtocolV1 method processes multiple requests on the same HTT…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-362"],"vendor":"redhat","product":"build_of_apache_camel_-_hawtio","affected":["build_of_apache_camel_-_hawtio","build_of_apache_camel_for_spring_boot","build_of_keycloak","data_grid = 8.0.0","integration_camel_k","jboss_enterprise_application_platform = 7.0.0","jboss_enterprise_application_platform = 8.0.0","jboss_fuse = 7.0.0","process_automation = 7.0","single_sign-on = 7.0"],"patched":["jboss_enterprise_application_platform_7_3_eus_for_rhel_7_server","jboss_eap_7_4_for_rhel_7_server","jboss_eap_7_4_for_rhel 8","jboss_eap_8_0_for_rhel 8","jboss_eap_7_4_for_rhel 9","jboss_eap_8_0_for_rhel 9","hawtio_4_0_0_for_red_hat_build_of_apache_camel 4","jboss_enterprise_application_platform 7","jboss_enterprise_application_platform 8","build_of_apache_camel_3_20_7_for_spring_boot","build_of_apache_camel_4_4_2_for_spring_boot"],"published":"2024-08-21","updated":"2026-09-24","sourceUpdated":"2026-09-24T04:17:34.743","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2024-7885","references":[{"url":"https://access.redhat.com/errata/RHSA-2024:11023","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:6508","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:6883","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:7441","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:7442","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:7735","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:7736","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:8080","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:16667","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:0743","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2024-7885","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2305290","label":"secalert@redhat.com"},{"url":"https://security.netapp.com/advisory/ntap-20241011-0004/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-7885.json"},{"url":"https://www.cve.org/CVERecord?id=CVE-2024-7885"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-7885"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2024-08-21T15:21:22.416004Z"},"epss":0.02644,"epssPercentile":0.8496,"ingestedAt":"2026-08-04T08:38:40.840Z","slug":"CVE-2024-7885","body":"## Overview\n\nA vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue occurs when the parseProxyProtocolV1 method processes multiple requests on the same HTTP connection. As a result, different requests may share the same StringBuilder instance, potentially leading to information leakage between requests or responses. In some cases, a value from a previous request or response may be erroneously reused, which could lead to unintended data exposure. This issue primarily results in errors and connection termination but creates a risk of data leakage in multi-request environments.\n\n## Affected\n\n- `build_of_apache_camel_-_hawtio`\n- `build_of_apache_camel_for_spring_boot`\n- `build_of_keycloak`\n- `data_grid = 8.0.0`\n- `integration_camel_k`\n- `jboss_enterprise_application_platform = 7.0.0`\n- `jboss_enterprise_application_platform = 8.0.0`\n- `jboss_fuse = 7.0.0`\n- `process_automation = 7.0`\n- `single_sign-on = 7.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **RHSA-2025:16667** · Red Hat · fixed in: Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server · released 2025-09-25 · [advisory](https://access.redhat.com/errata/RHSA-2025:16667)\n- **RHSA-2026:0743** · Red Hat · fixed in: Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server · released 2026-01-19 · [advisory](https://access.redhat.com/errata/RHSA-2026:0743)\n- **RHSA-2024:7736** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 for RHEL 7 Server, Red Hat JBoss EAP 7.4 for RHEL 8, Red Hat JBoss EAP 7.4 for RHEL 9 · released 2024-10-07 · [advisory](https://access.redhat.com/errata/RHSA-2024:7736)\n- **RHSA-2024:7441** · Red Hat · fixed in: Red Hat JBoss EAP 8.0 for RHEL 8, Red Hat JBoss EAP 8.0 for RHEL 9 · released 2024-10-01 · [advisory](https://access.redhat.com/errata/RHSA-2024:7441)\n- **RHSA-2024:11023** · Red Hat · fixed in: HawtIO 4.0.0 for Red Hat build of Apache Camel 4 · released 2024-12-12 · [advisory](https://access.redhat.com/errata/RHSA-2024:11023)\n- **RHSA-2024:7735** · Red Hat · fixed in: Red Hat JBoss Enterprise Application Platform 7 · released 2024-10-07 · [advisory](https://access.redhat.com/errata/RHSA-2024:7735)\n- **RHSA-2024:7442** · Red Hat · fixed in: Red Hat JBoss Enterprise Application Platform 8 · released 2024-10-01 · [advisory](https://access.redhat.com/errata/RHSA-2024:7442)\n- **RHSA-2024:6883** · Red Hat · fixed in: Red Hat build of Apache Camel 3.20.7 for Spring Boot · released 2024-09-19 · [advisory](https://access.redhat.com/errata/RHSA-2024:6883)\n- **RHSA-2024:6508** · Red Hat · fixed in: Red Hat build of Apache Camel 4.4.2 for Spring Boot · released 2024-09-09 · [advisory](https://access.redhat.com/errata/RHSA-2024:6508)\n- **Red Hat VEX** · Important · affected: Red Hat build of Apache Camel - HawtIO 4, Red Hat build of Apache Camel for Spring Boot 3, Red Hat Build of Keycloak, Red Hat Data Grid 8, Red Hat Fuse 7, Red Hat Integration Camel K 1, … · no fix planned: Red Hat JBoss Data Grid 7, Red Hat Process Automation 7, Red Hat Data Grid 8, Red Hat Fuse 7, … · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-7885.json)\n- **RHSA-2024:8080** · Red Hat · fixed in: Red Hat JBoss Enterprise Application Platform · released 2024-10-14 · [advisory](https://access.redhat.com/errata/RHSA-2024:8080)","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":41.3,"likelihood":0.5,"exploitation":0,"ransomware":0},"changes":[]}