Description
A flaw was found in JBossWeb in versions before 7.5.31.Final-redhat-3. The fix for CVE-2020-13935 was incomplete in JBossWeb, leaving it vulnerable to a denial of service attack when sending multiple requests with invalid payload length in a WebSocket frame. The highest threat from this vulnerability is to system availability.
Remediation
References
Related Vulnerabilities
OpenSSL Cryptographic Issues Vulnerability (CVE-2015-0205)
WordPress Plugin Inline Related Posts Multiple Cross-Site Scripting Vulnerabilities (3.0.4)
Drupal Incorrect Authorization Vulnerability (CVE-2017-6377)
WordPress Plugin DeMomentSomTres Subscribe Cross-Site Scripting (201909190900)
Jboss EAP Improper Input Validation Vulnerability (CVE-2011-4575)