Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2022-2053 Details

Description

When a POST request comes through AJP and the request exceeds the max-post-size limit (maxEntitySize), Undertow's AjpServerRequestConduit implementation closes a connection without sending any response to the client/proxy. This behavior results in that a front-end proxy marking the backend worker (application server) as an error state and not forward requests to the worker for a while. In mod_cluster, this continues until the next STATUS request (10 seconds intervals) from the application server updates the server state. So, in the worst case, it can result in "All workers are in error state" and mod_cluster responds "503 Service Unavailable" for a while (up to 10 seconds). In mod_proxy_balancer, it does not forward requests to the worker until the "retry" timeout passes. However, luckily, mod_proxy_balancer has "forcerecovery" setting (On by default; this parameter can force the immediate recovery of all workers without considering the retry parameter of the workers if all workers of a balancer are in error state.). So, unlike mod_cluster, mod_proxy_balancer does not result in responding "503 Service Unavailable". An attacker could use this behavior to send a malicious request and trigger server errors, resulting in DoS (denial of service). This flaw was fixed in Undertow 2.2.19.Final, Undertow 2.3.0.Alpha2.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-400Uncontrolled Resource Consumption[email protected]
CWE-400Uncontrolled Resource Consumption[email protected]

Affected Products

ProductVersions
redhat integration camel k
All versions

CPE

  • cpe:2.3:a:redhat:integration_camel_k:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
redhat jboss fuse
7.0.0

CPE

  • cpe:2.3:a:redhat:jboss_fuse:7.0.0:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
redhat undertow
< 2.2.19
2.3.0 alpha1

CPE

  • cpe:2.3:a:redhat:undertow:*:*:*:*:*:*:*:*
  • cpe:2.3:a:redhat:undertow:2.3.0:alpha1:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

4 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2022-2053
NVD Published Date:
Aug 5, 2022
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2022-2053 Details - Not Deferred