cbcvebase.
CVE-2022-2764
published 2022-09-01

CVE-2022-2764: A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations.

medium4.9CVSS 3.1
AVNACLPRHUINSUCNINAH
A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations.

Affected

8 ranges
VendorProductVersion rangeFixed in
debianundertow< undertow 2.2.21-1 (forky)undertow 2.2.21-1 (forky)
redhatjboss_enterprise_application_platform
redhatjboss_fuse
redhatsingle_sign-on
redhatundertow
redhatundertow
redhatundertow>= 0 < 2.2.21-12.2.21-1
redhatundertow2.0.0 – 2.2.19

CVSS provenance

nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
osv4.9MEDIUM