CVE-2022-2764
published 2022-09-01CVE-2022-2764: A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations.
PriorityP419medium4.9CVSS 3.1
AVNACLPRHUINSUCNINAH
EPSS
0.79%
52.1th percentile
A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | undertow | < undertow 2.2.21-1 (forky) | undertow 2.2.21-1 (forky) |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_fuse | — | — |
| redhat | single_sign-on | — | — |
| redhat | undertow | — | — |
| redhat | undertow | — | — |
| redhat | undertow | >= 0 < 2.2.21-1 | 2.2.21-1 |
| redhat | undertow | 2.0.0 – 2.2.19 | — |
CVSS provenance
nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
osv4.9MEDIUM
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Undertow: DoS can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations
vendor_redhat·2022-08-11·CVSS 4.9
CVE-2022-2764 [MEDIUM] Undertow: DoS can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations
Undertow: DoS can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations
A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations.
A flaw was found in Undertow with EJB invocations. This flaw allows an attacker to generate a valid HTTP request and send it to the server on an established connection after removing the LAST_CHUNK from the bytes, causing a denial of service.
Package: undertow (Red Hat build of Quarkus) - Not affected
Package: quarkus-http (Red Hat build of Quarkus) - Not affected
Package: undertow (Red Hat Data Grid 8) - Fix deferred
Package: undertow (Red Hat Decision Manager 7) - Not affected
Package: undertow (Red Hat Fuse 7) - Fix deferred
Package: undertow (
Debian
CVE-2022-2764: undertow - A flaw was found in Undertow. Denial of service can be achieved as Undertow serv...
vendor_debian·2022·CVSS 4.9
CVE-2022-2764 [MEDIUM] CVE-2022-2764: undertow - A flaw was found in Undertow. Denial of service can be achieved as Undertow serv...
A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations.
Scope: local
forky: resolved (fixed in 2.2.21-1)
sid: resolved (fixed in 2.2.21-1)
VulDB
Undertow EJB Invocation resource consumption (EUVD-2022-35006 / Nessus ID 253272)
vuldb·2026-05-27·CVSS 4.9
CVE-2022-2764 [MEDIUM] Undertow EJB Invocation resource consumption (EUVD-2022-35006 / Nessus ID 253272)
A vulnerability marked as problematic has been reported in Undertow. Affected by this vulnerability is an unknown functionality of the component EJB Invocation Handler. This manipulation causes resource consumption.
This vulnerability is tracked as CVE-2022-2764. The attack is only possible within the local network. No exploit exists.
GHSA
GHSA-xpxq-cp94-87j2: A flaw was found in Undertow
ghsa_unreviewed·2022-09-02
CVE-2022-2764 [MEDIUM] GHSA-xpxq-cp94-87j2: A flaw was found in Undertow
A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations.
OSV
CVE-2022-2764: A flaw was found in Undertow
osv·2022-09-01·CVSS 4.9
CVE-2022-2764 [MEDIUM] CVE-2022-2764: A flaw was found in Undertow
A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-09-01
Published