CVE-2023-1108: Netapp Oncommand Workflow Automation

High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.

A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.

Affected products

  • Netapp Oncommand Workflow Automation: affected versions not specified
  • Red Hat Build Of Quarkus: affected versions not specified
  • Red Hat Decision Manager: version 7.0 only
  • Red Hat Fuse: version 1.0.0 only
  • Red Hat Integration Camel K: affected versions not specified
  • Red Hat Integration Service Registry: affected versions not specified
  • Red Hat JBoss Enterprise Application Platform: affected versions not specified; version 7.4 only
  • Red Hat JBoss Enterprise Application Platform Expansion Pack: affected versions not specified
  • Red Hat Openshift Application Runtimes: affected versions not specified
  • Red Hat Openshift Container Platform: version 4.11 only; version 4.12 only
  • Red Hat Openshift Container Platform For Linuxone: version 4.9 only; version 4.10 only
  • Red Hat Openshift Container Platform For Power: version 4.9 only; version 4.10 only
  • Red Hat Openstack Platform: version 13.0 only
  • Red Hat Process Automation: version 7.0 only
  • Red Hat Single Sign-On: affected versions not specified; version 7.6 only
  • Red Hat Undertow: before 2.2.24 (fixed in 2.2.24); from 2.3.0, before 2.3.5 (fixed in 2.3.5)

Published 2023-09-14. Last modified 2026-06-17.