CVE-2024-3653: Red Hat Openshift Serverless
Medium severity, CVSS 5.3. EPSS: 1.9% chance of exploitation in the next 30 days.
A vulnerability was found in Undertow. This issue requires enabling the learning-push handler in the server's config, which is disabled by default, leaving the maxAge config in the handler unconfigured. The default is -1, which makes the handler vulnerable. If someone overwrites that config, the server is not subject to the attack. The attacker needs to be able to reach the server with a normal HTTP request.
Affected products
- Red Hat Openshift Serverless
- Red Hat Red Hat Build Of Apache Camel - Hawtio 4
- Red Hat Red Hat Build Of Apache Camel 4 For Quarkus 3
- Red Hat Red Hat Build Of Apache Camel For Spring Boot 4
- Red Hat Red Hat Build Of Apicurio Registry 2
- Red Hat Red Hat Build Of Keycloak
- Red Hat Red Hat Build Of Optaplanner 8
- Red Hat Red Hat Build Of Quarkus
- Red Hat Red Hat Build Of Quarkus 3.8.6.redhat: before 5.2.4.redhat-00001 (fixed in 5.2.4.redhat-00001)
- Red Hat Red Hat Data Grid 8
- Red Hat Red Hat Fuse 7
- Red Hat Red Hat Integration Camel K 1
- Red Hat Red Hat Integration Camel Quarkus 2
- Red Hat Red Hat JBoss Data Grid 7
- Red Hat Red Hat JBoss Enterprise Application Platform: before 2.2.33.SP1-redhat-00001 (fixed in 2.2.33.SP1-redhat-00001)
- Red Hat Red Hat JBoss Enterprise Application Platform 7.4 For Rhel 8: before 0:2.2.33-1.SP1_redhat_00001.1.el8eap (fixed in 0:2.2.33-1.SP1_redhat_00001.1.el8eap)
- Red Hat Red Hat JBoss Enterprise Application Platform 7.4 For Rhel 9: before 0:2.2.33-1.SP1_redhat_00001.1.el9eap (fixed in 0:2.2.33-1.SP1_redhat_00001.1.el9eap)
- Red Hat Red Hat JBoss Enterprise Application Platform 7.4 On Rhel 7: before 0:2.2.33-1.SP1_redhat_00001.1.el7eap (fixed in 0:2.2.33-1.SP1_redhat_00001.1.el7eap)
- Red Hat Red Hat JBoss Enterprise Application Platform 8
- Red Hat Red Hat JBoss Enterprise Application Platform Expansion Pack
- Red Hat Red Hat JBoss Fuse Service Works 6
- Red Hat Red Hat Process Automation 7
- Red Hat Red Hat Single Sign-On 7
- Red Hat Streams For Apache Kafka
Published 2024-07-08. Last modified 2026-09-08.