ZeroHour

CVE-2021-3597

CVSS 3.1
5.9 medium
EPSS
1%p64
Published
()
Modified
Description

A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circumstances, resulting in a denial of service. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.35.SP1, prior to 2.2.6.SP1, prior to 2.2.7.SP1, prior to 2.0.36.SP1, prior to 2.2.9.Final and prior to 2.0.39.Final.

Vendors
redhatnetapp
Products
fuse, jboss enterprise application platform, openshift application runtimes, single sign-on, undertow, active iq unified manager, oncommand insight, oncommand workflow automation
Weakness
CWE-362
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.