Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-339q-62wm-c39w

Опубликовано: 15 июл. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Undertow vulnerable to Denial of Service (DoS) attacks

Undertow client side invocation timeout raised when calling over HTTP2, this vulnerability can allow attacker to carry out denial of service (DoS) attacks in versions less than 2.2.15 Final.

Пакеты

Наименование

io.undertow:undertow-core

maven
Затронутые версииВерсия исправления

< 2.2.15

2.2.15

EPSS

Процентиль: 54%
0.00309
Низкий

7.5 High

CVSS3

Дефекты

CWE-214
CWE-400
CWE-668

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 3 лет назад

A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out denial of service attacks.

CVSS3: 7.5
redhat
около 4 лет назад

A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out denial of service attacks.

CVSS3: 7.5
nvd
больше 3 лет назад

A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out denial of service attacks.

CVSS3: 7.5
debian
больше 3 лет назад

A flaw was found in Undertow that tripped the client-side invocation t ...

EPSS

Процентиль: 54%
0.00309
Низкий

7.5 High

CVSS3

Дефекты

CWE-214
CWE-400
CWE-668