---
id: CVE-2024-7885
title: >-
  A vulnerability was found in Undertow where the ProxyProtocolReadListener
  reuses the same StringBuilder instance across multiple requests
summary: >-
  A vulnerability was found in Undertow where the ProxyProtocolReadListener
  reuses the same StringBuilder instance across multiple requests. This issue
  occurs when the parseProxyProtocolV1 method processes multiple requests on the
  same HTT…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-362
vendor: redhat
product: build_of_apache_camel_-_hawtio
affected:
  - build_of_apache_camel_-_hawtio
  - build_of_apache_camel_for_spring_boot
  - build_of_keycloak
  - data_grid = 8.0.0
  - integration_camel_k
  - jboss_enterprise_application_platform = 7.0.0
  - jboss_enterprise_application_platform = 8.0.0
  - jboss_fuse = 7.0.0
  - process_automation = 7.0
  - single_sign-on = 7.0
patched:
  - jboss_enterprise_application_platform_7_3_eus_for_rhel_7_server
  - jboss_eap_7_4_for_rhel_7_server
  - jboss_eap_7_4_for_rhel 8
  - jboss_eap_8_0_for_rhel 8
  - jboss_eap_7_4_for_rhel 9
  - jboss_eap_8_0_for_rhel 9
  - hawtio_4_0_0_for_red_hat_build_of_apache_camel 4
  - jboss_enterprise_application_platform 7
  - jboss_enterprise_application_platform 8
  - build_of_apache_camel_3_20_7_for_spring_boot
  - build_of_apache_camel_4_4_2_for_spring_boot
published: '2024-08-21'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T04:17:34.743'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-7885'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2024:11023'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:6508'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:6883'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:7441'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:7442'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:7735'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:7736'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:8080'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:16667'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:0743'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2024-7885'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2305290'
    label: secalert@redhat.com
  - url: 'https://security.netapp.com/advisory/ntap-20241011-0004/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-7885.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2024-7885'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-7885'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2024-08-21T15:21:22.416004Z'
epss: 0.02644
epssPercentile: 0.84961
ingestedAt: '2026-08-04T08:38:40.840Z'
---

## Overview

A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue occurs when the parseProxyProtocolV1 method processes multiple requests on the same HTTP connection. As a result, different requests may share the same StringBuilder instance, potentially leading to information leakage between requests or responses. In some cases, a value from a previous request or response may be erroneously reused, which could lead to unintended data exposure. This issue primarily results in errors and connection termination but creates a risk of data leakage in multi-request environments.

## Affected

- `build_of_apache_camel_-_hawtio`
- `build_of_apache_camel_for_spring_boot`
- `build_of_keycloak`
- `data_grid = 8.0.0`
- `integration_camel_k`
- `jboss_enterprise_application_platform = 7.0.0`
- `jboss_enterprise_application_platform = 8.0.0`
- `jboss_fuse = 7.0.0`
- `process_automation = 7.0`
- `single_sign-on = 7.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2025:16667** · Red Hat · fixed in: Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server · released 2025-09-25 · [advisory](https://access.redhat.com/errata/RHSA-2025:16667)
- **RHSA-2026:0743** · Red Hat · fixed in: Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Server · released 2026-01-19 · [advisory](https://access.redhat.com/errata/RHSA-2026:0743)
- **RHSA-2024:7736** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 for RHEL 7 Server, Red Hat JBoss EAP 7.4 for RHEL 8, Red Hat JBoss EAP 7.4 for RHEL 9 · released 2024-10-07 · [advisory](https://access.redhat.com/errata/RHSA-2024:7736)
- **RHSA-2024:7441** · Red Hat · fixed in: Red Hat JBoss EAP 8.0 for RHEL 8, Red Hat JBoss EAP 8.0 for RHEL 9 · released 2024-10-01 · [advisory](https://access.redhat.com/errata/RHSA-2024:7441)
- **RHSA-2024:11023** · Red Hat · fixed in: HawtIO 4.0.0 for Red Hat build of Apache Camel 4 · released 2024-12-12 · [advisory](https://access.redhat.com/errata/RHSA-2024:11023)
- **RHSA-2024:7735** · Red Hat · fixed in: Red Hat JBoss Enterprise Application Platform 7 · released 2024-10-07 · [advisory](https://access.redhat.com/errata/RHSA-2024:7735)
- **RHSA-2024:7442** · Red Hat · fixed in: Red Hat JBoss Enterprise Application Platform 8 · released 2024-10-01 · [advisory](https://access.redhat.com/errata/RHSA-2024:7442)
- **RHSA-2024:6883** · Red Hat · fixed in: Red Hat build of Apache Camel 3.20.7 for Spring Boot · released 2024-09-19 · [advisory](https://access.redhat.com/errata/RHSA-2024:6883)
- **RHSA-2024:6508** · Red Hat · fixed in: Red Hat build of Apache Camel 4.4.2 for Spring Boot · released 2024-09-09 · [advisory](https://access.redhat.com/errata/RHSA-2024:6508)
- **Red Hat VEX** · Important · affected: Red Hat build of Apache Camel - HawtIO 4, Red Hat build of Apache Camel for Spring Boot 3, Red Hat Build of Keycloak, Red Hat Data Grid 8, Red Hat Fuse 7, Red Hat Integration Camel K 1, … · no fix planned: Red Hat JBoss Data Grid 7, Red Hat Process Automation 7, Red Hat Data Grid 8, Red Hat Fuse 7, … · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-7885.json)
- **RHSA-2024:8080** · Red Hat · fixed in: Red Hat JBoss Enterprise Application Platform · released 2024-10-14 · [advisory](https://access.redhat.com/errata/RHSA-2024:8080)
