LiveActive security incident?Get immediate response
CVE Record

CVE-2023-5379: Undertow: ajp request closes connection exceeding maxrequestsize

A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error state by mod_cluster in httpd, causing JBoss EAP to close the TCP connection without returning an AJP response. This happens because mod_proxy_cluster marks the JBoss EAP instance as an error worker when the TCP connection is closed from the backend after sending the AJP request without receiving an AJP response, and stops forwarding. This issue could allow a malicious user could to repeatedly send requests that exceed the max-header-size, causing a Denial of Service (DoS).

HighCVSS 7.5Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

A remote, unauthenticated attacker may disrupt affected JBoss EAP services by repeatedly sending oversized AJP requests. The backend closes connections without responding, causing the front-end cluster proxy to mark application servers unavailable and stop forwarding traffic. This can create a denial of service; the supplied evidence does not establish data theft or active exploitation.

Executive priority

Prioritize affected externally reachable or business-critical JBoss clusters. Patch through Red Hat’s applicable advisories and verify every node. Treat this as an availability risk rather than a confirmed confidentiality breach. If exposure is isolated and compensating controls prevent untrusted AJP traffic, schedule remediation promptly within normal high-severity timelines.

Technical view

When an AJP request exceeds the listener’s max-header-size, Undertow closes the backend TCP connection without an AJP response. mod_proxy_cluster then marks the JBoss EAP worker as erroneous and stops forwarding requests. Repetition can deny service. The supplied affected inventory identifies specific JBoss EAP 7.1 and 7.3 EUS package builds on RHEL 7.

Likely exposure

Exposure requires an affected JBoss EAP deployment using an AJP listener with httpd mod_cluster or mod_proxy_cluster, where untrusted oversized requests can reach that path. Internet-facing proxies increase concern, but internal services may also be exposed through reachable intermediary systems. The bundle does not establish whether AJP is enabled by default.

Exploitation context

The behavior is remotely triggerable, requires no privileges or user interaction, and is described as low complexity. Repeated malformed requests could remove workers from service. CVE is not identified as CISA KEV, and the supplied sources provide no evidence of active exploitation or a public exploit.

Researcher notes

The narrative describes denial of service, but the supplied CVSS vector encodes confidentiality impact as high and availability impact as none. That inconsistency should be checked against current vendor scoring before relying on component metrics. The package list appears advisory-specific and should not be generalized beyond the named JBoss EAP EUS releases and builds.

Mitigation direction

  • Apply the applicable Red Hat security update identified in vendor advisories.
  • Confirm update eligibility for the deployed JBoss EAP EUS release and RHEL package set.
  • Restrict untrusted access to AJP listeners and cluster-proxy paths where operationally feasible.
  • Review current Red Hat guidance before using configuration changes as compensating controls.

Validation and detection

  • Inventory JBoss EAP 7.1 and 7.3 EUS deployments and installed package versions.
  • Identify AJP listeners and their max-header-size settings.
  • Verify whether httpd mod_cluster or mod_proxy_cluster forwards traffic to affected backends.
  • Confirm applicable Red Hat errata packages are installed across every cluster node.
  • Review proxy and backend logs for worker-error transitions following closed AJP connections.
Prepared
Confidence
medium
Sources
6

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-770: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2023-5379 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
7.5 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
5Timeline events
2ADP providers
6Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: yesTechnical Impact: partial

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
7.5CVSS 3.1HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N3.93.6redhat

Vulnerability scoring details

Base CVSS 3.1 score

7.5High
CVSS 3.1 vector shape for CVE-2023-5379Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. Source timelineredhat

    Reported to Red Hat.

  2. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  3. Source timelineredhat

    Made public.

  4. CVE publishedCVE Program

    The CVE record was published.

  5. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CVECVE Program Container
CISA-ADPCISA ADP Vulnrichment
other:ssvc

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
Red HatRed Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7eap7-glassfish-el, 0:3.0.1-4.b08_redhat_00005.1.ep7.el7affected
Red HatRed Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7eap7-hibernate, 0:5.1.17-3.Final_redhat_00004.1.ep7.el7affected
Red HatRed Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7eap7-jackson-databind, 0:2.8.11.6-3.SP1_redhat_00003.1.ep7.el7affected
Red HatRed Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7eap7-jboss-ejb-client, 0:4.0.12-1.Final_redhat_00002.1.ep7.el7affected
Red HatRed Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7eap7-netty, 0:4.1.63-2.Final_redhat_00003.1.ep7.el7affected
Red HatRed Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7eap7-undertow, 0:1.4.18-16.SP14_redhat_00001.1.ep7.el7affected
Red HatRed Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7eap7-wildfly, 0:7.1.11-4.GA_redhat_00002.1.ep7.el7affected
Red HatRed Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7eap7-wildfly-elytron, 0:1.1.14-1.Final_redhat_00001.1.ep7.el7affected
Red HatRed Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7eap7-wildfly-http-client, 0:1.0.21-1.Final_redhat_00001.1.ep7.el7affected
Red HatRed Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7eap7-wildfly-naming-client, 0:1.0.13-1.Final_redhat_00001.1.ep7.el7affected
Red HatRed Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7eap7-wildfly-openssl, 0:1.0.12-1.Final_redhat_00001.1.ep7.el7affected
Red HatRed Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7eap7-wildfly-openssl-linux, 0:1.0.12-6.Final_redhat_00001.1.ep7.el7affected
Red HatRed Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7eap7-jackson-annotations, 0:2.10.4-3.redhat_00006.1.el7eapaffected
Red HatRed Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7eap7-jackson-core, 0:2.10.4-3.redhat_00006.1.el7eapaffected
Red HatRed Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7eap7-jackson-databind, 0:2.10.4-5.redhat_00006.1.el7eapaffected
Red HatRed Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7eap7-jackson-jaxrs-providers, 0:2.10.4-3.redhat_00006.1.el7eapaffected
Red HatRed Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7eap7-jackson-modules-base, 0:2.10.4-5.redhat_00006.1.el7eapaffected
Red HatRed Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7eap7-jackson-modules-java8, 0:2.10.4-2.redhat_00006.1.el7eapaffected
Red HatRed Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7eap7-jboss-server-migration, 0:1.7.2-16.Final_redhat_00017.1.el7eapaffected
Red HatRed Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7eap7-netty, 0:4.1.63-5.Final_redhat_00003.1.el7eapaffected
Red HatRed Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7eap7-undertow, 0:2.0.41-4.SP5_redhat_00001.1.el7eapaffected
Red HatRed Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7eap7-wildfly, 0:7.3.14-3.GA_redhat_00002.1.el7eapaffected
Red HatRed Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7eap7-wildfly-elytron, 0:1.10.17-1.Final_redhat_00001.1.el7eapaffected
Red HatRed Hat build of Quarkusquarkus-undertowunaffected
Red HatRed Hat Data Grid 8undertowunaffected
Red HatRed Hat Decision Manager 7undertowunknown
Red HatRed Hat Fuse 7undertowunknown
Red HatRed Hat JBoss Data Grid 7undertowunknown
Red HatRed Hat JBoss Enterprise Application Platform 7undertowaffected
Red HatRed Hat JBoss Fuse 6undertowunknown
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-770 · source CWE mapping

Allocation of Resources Without Limits or Throttling

Allocation of Resources Without Limits or Throttling represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.