ZeroHour

CVE-2021-3629

CVSS 3.1
5.9 medium
EPSS
1%p69
Published
()
Modified
Description

A flaw was found in Undertow. A potential security issue in flow control handling by the browser over http/2 may potentially cause overhead or a denial of service in the server. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.40.Final and prior to 2.2.11.Final.

Vendors
redhatnetapp
Products
integration, jboss enterprise application platform, single sign-on, undertow, wildfly core, active iq unified manager, oncommand insight, oncommand workflow automation
Weakness
CWE-400
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.