CVE-2021-3597
published 2022-05-24CVE-2021-3597: A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circumstances, resulting in a denial of service. The highest…
PriorityP428medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
1.06%
60.8th percentile
A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circumstances, resulting in a denial of service. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.35.SP1, prior to 2.2.6.SP1, prior to 2.2.7.SP1, prior to 2.0.36.SP1, prior to 2.2.9.Final and prior to 2.0.39.Final.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | undertow | < undertow 2.2.10-1 (forky) | undertow 2.2.10-1 (forky) |
| redhat | fuse | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | undertow | < 2.0.35 | 2.0.35 |
| redhat | undertow | — | — |
| redhat | undertow | — | — |
| redhat | undertow | — | — |
| redhat | undertow | — | — |
| redhat | undertow | — | — |
| redhat | undertow | — | — |
| redhat | undertow | — | — |
| redhat | undertow | >= 0 < 2.2.10-1 | 2.2.10-1 |
| redhat | undertow | >= 2.2.0 < 2.2.6 | 2.2.6 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:N/I:N/A:P
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_oracle5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
undertow Race Condition vulnerability
osv·2022-05-25
CVE-2021-3597 [MEDIUM] undertow Race Condition vulnerability
undertow Race Condition vulnerability
A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circumstances, resulting in a denial of service. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.35.SP1, prior to 2.2.6.SP1, prior to 2.2.7.SP1, prior to 2.0.36.SP1, prior to 2.2.9.Final and prior to 2.0.39.Final.
GHSA
undertow Race Condition vulnerability
ghsa·2022-05-25
CVE-2021-3597 [MEDIUM] CWE-362 undertow Race Condition vulnerability
undertow Race Condition vulnerability
A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circumstances, resulting in a denial of service. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.35.SP1, prior to 2.2.6.SP1, prior to 2.2.7.SP1, prior to 2.0.36.SP1, prior to 2.2.9.Final and prior to 2.0.39.Final.
OSV
CVE-2021-3597: A flaw was found in undertow
osv·2022-05-24·CVSS 5.9
CVE-2021-3597 [MEDIUM] CVE-2021-3597: A flaw was found in undertow
A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circumstances, resulting in a denial of service. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.35.SP1, prior to 2.2.6.SP1, prior to 2.2.7.SP1, prior to 2.0.36.SP1, prior to 2.2.9.Final and prior to 2.0.39.Final.
Oracle
Oracle Oracle Communications Risk Matrix: Signaling (undertow) — CVE-2021-3597
vendor_oracle·2022-10-15·CVSS 5.9
CVE-2021-3597 [MEDIUM] Oracle Oracle Communications Risk Matrix: Signaling (undertow) — CVE-2021-3597
Oracle Oracle Communications Risk Matrix: Signaling (undertow) vulnerability
CVE: CVE-2021-3597
CVSS: 5.9
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Red Hat
undertow: HTTP2SourceChannel fails to write final frame under some circumstances may lead to DoS
vendor_redhat·2021-06-11·CVSS 5.9
CVE-2021-3597 [MEDIUM] CWE-362 undertow: HTTP2SourceChannel fails to write final frame under some circumstances may lead to DoS
undertow: HTTP2SourceChannel fails to write final frame under some circumstances may lead to DoS
A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circumstances, resulting in a denial of service. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.35.SP1, prior to 2.2.6.SP1, prior to 2.2.7.SP1, prior to 2.0.36.SP1, prior to 2.2.9.Final and prior to 2.0.39.Final.
A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circumstances, resulting in a denial of service. The highest threat from this vulnerability is availability.
Statement: Red Hat OpenStack Platform's OpenDaylight will not be updated for this flaw because it was deprecated as of OpenSta
Debian
CVE-2021-3597: undertow - A flaw was found in undertow. The HTTP2SourceChannel fails to write the final fr...
vendor_debian·2021·CVSS 5.9
CVE-2021-3597 [MEDIUM] CVE-2021-3597: undertow - A flaw was found in undertow. The HTTP2SourceChannel fails to write the final fr...
A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circumstances, resulting in a denial of service. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.35.SP1, prior to 2.2.6.SP1, prior to 2.2.7.SP1, prior to 2.0.36.SP1, prior to 2.2.9.Final and prior to 2.0.39.Final.
Scope: local
forky: resolved (fixed in 2.2.10-1)
sid: resolved (fixed in 2.2.10-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-05-24
Published