CVE-2021-3690
published 2022-08-23CVE-2021-3690: A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a…
PriorityP335high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.39%
69.2th percentile
A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is availability.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | undertow | < undertow 2.2.10-1 (forky) | undertow 2.2.10-1 (forky) |
| redhat | fuse | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | undertow | < 2.0.40 | 2.0.40 |
| redhat | undertow | — | — |
| redhat | undertow | >= 0 < 2.2.10-1 | 2.2.10-1 |
| redhat | undertow | >= 2.1.0 < 2.2.10 | 2.2.10 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2021-3690: A flaw was found in Undertow
osv·2022-08-23·CVSS 7.5
CVE-2021-3690 [HIGH] CVE-2021-3690: A flaw was found in Undertow
A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is availability.
GHSA
Undertow vulnerable to memory exhaustion due to buffer leak
ghsa·2022-07-15
CVE-2021-3690 [HIGH] CWE-400 Undertow vulnerable to memory exhaustion due to buffer leak
Undertow vulnerable to memory exhaustion due to buffer leak
Buffer leak on incoming WebSocket PONG message(s) in Undertow before 2.0.40 and 2.2.10 can lead to memory exhaustion and allow a denial of service.
OSV
Undertow vulnerable to memory exhaustion due to buffer leak
osv·2022-07-15
CVE-2021-3690 [HIGH] Undertow vulnerable to memory exhaustion due to buffer leak
Undertow vulnerable to memory exhaustion due to buffer leak
Buffer leak on incoming WebSocket PONG message(s) in Undertow before 2.0.40 and 2.2.10 can lead to memory exhaustion and allow a denial of service.
Oracle
Oracle Oracle Communications Risk Matrix: NSSF (Undertow) — CVE-2021-3690
vendor_oracle·2022-04-15·CVSS 7.5
CVE-2021-3690 [HIGH] Oracle Oracle Communications Risk Matrix: NSSF (Undertow) — CVE-2021-3690
Oracle Oracle Communications Risk Matrix: NSSF (Undertow) vulnerability
CVE: CVE-2021-3690
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Red Hat
undertow: buffer leak on incoming websocket PONG message may lead to DoS
vendor_redhat·2021-07-30·CVSS 7.5
CVE-2021-3690 [HIGH] CWE-401 undertow: buffer leak on incoming websocket PONG message may lead to DoS
undertow: buffer leak on incoming websocket PONG message may lead to DoS
A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is availability.
A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is availability.
Statement: Although Red Hat OpenStack Platform packages the vulnerable code in Opendaylight, it does not use or support the undertow-encapsulating features. The security impact for RHOSP is therefore rated as Low and no update will be provided at this time.
Debian
CVE-2021-3690: undertow - A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG messa...
vendor_debian·2021·CVSS 7.5
CVE-2021-3690 [HIGH] CVE-2021-3690: undertow - A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG messa...
A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is availability.
Scope: local
forky: resolved (fixed in 2.2.10-1)
sid: resolved (fixed in 2.2.10-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/security/cve/CVE-2021-3690https://bugzilla.redhat.com/show_bug.cgi?id=1991299https://github.com/undertow-io/undertow/commit/c7e84a0b7efced38506d7d1dfea5902366973877https://issues.redhat.com/browse/UNDERTOW-1935https://access.redhat.com/security/cve/CVE-2021-3690https://bugzilla.redhat.com/show_bug.cgi?id=1991299https://github.com/undertow-io/undertow/commit/c7e84a0b7efced38506d7d1dfea5902366973877https://issues.redhat.com/browse/UNDERTOW-1935
2022-08-23
Published