CVE-2024-3884: Red Hat Openshift Serverless
High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.
A flaw was found in Undertow that can cause remote denial of service attacks. When the server uses the FormEncodedDataDefinition.doParse(StreamSourceChannel) method to parse large form data encoding with application/x-www-form-urlencoded, the method will cause an OutOfMemory issue. This flaw allows unauthorized users to cause a remote denial of service (DoS) attack.
Affected products
- Red Hat Openshift Serverless
- Red Hat Red Hat Build Of Apache Camel - Hawtio 4
- Red Hat Red Hat Build Of Apache Camel 4 For Quarkus 3
- Red Hat Red Hat Build Of Apache Camel For Spring Boot 3
- Red Hat Red Hat Build Of Apache Camel For Spring Boot 4
- Red Hat Red Hat Build Of Apicurio Registry 2
- Red Hat Red Hat Build Of Keycloak
- Red Hat Red Hat Build Of Optaplanner 8
- Red Hat Red Hat Build Of Quarkus
- Red Hat Red Hat Data Grid 8
- Red Hat Red Hat Fuse 7
- Red Hat Red Hat Integration Camel K 1
- Red Hat Red Hat Integration Camel Quarkus 2
- Red Hat Red Hat JBoss Data Grid 7
- Red Hat Red Hat JBoss Enterprise Application Platform 7
- Red Hat Red Hat JBoss Enterprise Application Platform 7.1 Eus For Rhel 7: before 0:1.4.18-19.SP17_redhat_00001.1.ep7.el7 (fixed in 0:1.4.18-19.SP17_redhat_00001.1.ep7.el7); before 0:7.1.14-4.GA_redhat_00003.1.ep7.el7 (fixed in 0:7.1.14-4.GA_redhat_00003.1.ep7.el7)
- Red Hat Red Hat JBoss Enterprise Application Platform 7.3 Eus For Rhel 7: before 0:2.0.41-7.SP8_redhat_00001.1.el7eap (fixed in 0:2.0.41-7.SP8_redhat_00001.1.el7eap); before 0:7.3.17-5.GA_redhat_00006.1.el7eap (fixed in 0:7.3.17-5.GA_redhat_00006.1.el7eap)
- Red Hat Red Hat JBoss Enterprise Application Platform 7.4.24: before 2.2.39.Final-redhat-00001 (fixed in 2.2.39.Final-redhat-00001)
- Red Hat Red Hat JBoss Enterprise Application Platform 7.4 Els On Rhel 7: before 0:2.2.39-1.Final_redhat_00001.1.el7eap (fixed in 0:2.2.39-1.Final_redhat_00001.1.el7eap); before 0:7.4.24-4.GA_redhat_00002.1.el7eap (fixed in 0:7.4.24-4.GA_redhat_00002.1.el7eap)
- Red Hat Red Hat JBoss Enterprise Application Platform 7.4 Els On Rhel 8: before 0:2.2.39-1.Final_redhat_00001.1.el8eap (fixed in 0:2.2.39-1.Final_redhat_00001.1.el8eap); before 0:7.4.24-4.GA_redhat_00002.1.el8eap (fixed in 0:7.4.24-4.GA_redhat_00002.1.el8eap)
- Red Hat Red Hat JBoss Enterprise Application Platform 7.4 Els On Rhel 9: before 0:2.2.39-1.Final_redhat_00001.1.el9eap (fixed in 0:2.2.39-1.Final_redhat_00001.1.el9eap); before 0:7.4.24-4.GA_redhat_00002.1.el9eap (fixed in 0:7.4.24-4.GA_redhat_00002.1.el9eap)
- Red Hat Red Hat JBoss Enterprise Application Platform 8.0
- Red Hat Red Hat JBoss Enterprise Application Platform 8.0 For Rhel 8: before 0:1.83.0-1.redhat_00001.1.el8eap (fixed in 0:1.83.0-1.redhat_00001.1.el8eap); before 0:33.0.0-2.jre_redhat_00003.1.el8eap (fixed in 0:33.0.0-2.jre_redhat_00003.1.el8eap); before 0:4.0.6-1.redhat_00001.1.el8eap (fixed in 0:4.0.6-1.redhat_00001.1.el8eap); before 0:1.0.0-3.redhat_00009.1.el8eap (fixed in 0:1.0.0-3.redhat_00009.1.el8eap); before 0:2.0.2-1.Final_redhat_00001.1.el8eap (fixed in 0:2.0.2-1.Final_redhat_00001.1.el8eap); before 0:2.3.23-1.SP3_redhat_00001.1.el8eap (fixed in 0:2.3.23-1.SP3_redhat_00001.1.el8eap)
- Red Hat Red Hat JBoss Enterprise Application Platform 8.0 For Rhel 9: before 0:1.83.0-1.redhat_00001.1.el9eap (fixed in 0:1.83.0-1.redhat_00001.1.el9eap); before 0:33.0.0-2.jre_redhat_00003.1.el9eap (fixed in 0:33.0.0-2.jre_redhat_00003.1.el9eap); before 0:4.0.6-1.redhat_00001.1.el9eap (fixed in 0:4.0.6-1.redhat_00001.1.el9eap); before 0:1.0.0-3.redhat_00009.1.el9eap (fixed in 0:1.0.0-3.redhat_00009.1.el9eap); before 0:2.0.2-1.Final_redhat_00001.1.el9eap (fixed in 0:2.0.2-1.Final_redhat_00001.1.el9eap); before 0:2.3.23-1.SP3_redhat_00001.1.el9eap (fixed in 0:2.3.23-1.SP3_redhat_00001.1.el9eap)
- Red Hat Red Hat JBoss Enterprise Application Platform 8.1.6: before 2.3.24.SP2-redhat-00001 (fixed in 2.3.24.SP2-redhat-00001)
- and 7 more
Published 2025-12-03. Last modified 2026-09-26.