CVE-2021-3859
published 2022-08-26CVE-2021-3859: A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out…
PriorityP336high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.30%
67.2th percentile
A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out denial of service attacks.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | undertow | < undertow 2.2.16-1 (forky) | undertow 2.2.16-1 (forky) |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | single_sign-on | — | — |
| redhat | single_sign-on | — | — |
| redhat | undertow | < 2.2.15 | 2.2.15 |
| redhat | undertow | — | — |
| redhat | undertow | >= 0 < 2.2.16-1 | 2.2.16-1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2021-3859: A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2
osv·2022-08-26·CVSS 7.5
CVE-2021-3859 [HIGH] CVE-2021-3859: A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2
A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out denial of service attacks.
GHSA
Undertow vulnerable to Denial of Service (DoS) attacks
ghsa·2022-07-15
CVE-2021-3859 [HIGH] CWE-214 Undertow vulnerable to Denial of Service (DoS) attacks
Undertow vulnerable to Denial of Service (DoS) attacks
Undertow client side invocation timeout raised when calling over HTTP2, this vulnerability can allow attacker to carry out denial of service (DoS) attacks in versions less than 2.2.15 Final.
OSV
Undertow vulnerable to Denial of Service (DoS) attacks
osv·2022-07-15
CVE-2021-3859 [HIGH] Undertow vulnerable to Denial of Service (DoS) attacks
Undertow vulnerable to Denial of Service (DoS) attacks
Undertow client side invocation timeout raised when calling over HTTP2, this vulnerability can allow attacker to carry out denial of service (DoS) attacks in versions less than 2.2.15 Final.
Red Hat
undertow: client side invocation timeout raised when calling over HTTP2
vendor_redhat·2022-02-01·CVSS 7.5
CVE-2021-3859 [HIGH] CWE-214 undertow: client side invocation timeout raised when calling over HTTP2
undertow: client side invocation timeout raised when calling over HTTP2
A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out denial of service attacks.
A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out denial of service attacks.
Statement: Red Hat OpenStack Platform's OpenDaylight will not be updated for this flaw because it was deprecated as of OpenStack Platform 14 and is only receiving security fixes for Critical flaws.
Package: undertow (Red Hat build of Quarkus) - Not affected
Package: undertow (Red Hat Decision Manager 7) - Not affected
Package: undertow (Red Hat Integration
Debian
CVE-2021-3859: undertow - A flaw was found in Undertow that tripped the client-side invocation timeout wit...
vendor_debian·2021·CVSS 7.5
CVE-2021-3859 [HIGH] CVE-2021-3859: undertow - A flaw was found in Undertow that tripped the client-side invocation timeout wit...
A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out denial of service attacks.
Scope: local
forky: resolved (fixed in 2.2.16-1)
sid: resolved (fixed in 2.2.16-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/security/cve/CVE-2021-3859https://bugzilla.redhat.com/show_bug.cgi?id=2010378https://github.com/undertow-io/undertow/commit/e43f0ada3f4da6e8579e0020cec3cb1a81e487c2https://github.com/undertow-io/undertow/pull/1296https://issues.redhat.com/browse/UNDERTOW-1979https://security.netapp.com/advisory/ntap-20221201-0004/https://access.redhat.com/security/cve/CVE-2021-3859https://bugzilla.redhat.com/show_bug.cgi?id=2010378https://github.com/undertow-io/undertow/commit/e43f0ada3f4da6e8579e0020cec3cb1a81e487c2https://github.com/undertow-io/undertow/pull/1296https://issues.redhat.com/browse/UNDERTOW-1979https://security.netapp.com/advisory/ntap-20221201-0004/
2022-08-26
Published