Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mfhv-gwf8-4m88

Опубликовано: 25 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

undertow Race Condition vulnerability

A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circumstances, resulting in a denial of service. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.35.SP1, prior to 2.2.6.SP1, prior to 2.2.7.SP1, prior to 2.0.36.SP1, prior to 2.2.9.Final and prior to 2.0.39.Final.

Пакеты

Наименование

io.undertow:undertow-core

maven
Затронутые версииВерсия исправления

>= 2.1.0, <= 2.2.8.Final

2.2.9.Final

Наименование

io.undertow:undertow-core

maven
Затронутые версииВерсия исправления

<= 2.0.38.Final

2.0.39.Final

EPSS

Процентиль: 38%
0.00169
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 3 лет назад

A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circumstances, resulting in a denial of service. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.35.SP1, prior to 2.2.6.SP1, prior to 2.2.7.SP1, prior to 2.0.36.SP1, prior to 2.2.9.Final and prior to 2.0.39.Final.

CVSS3: 5.9
redhat
больше 4 лет назад

A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circumstances, resulting in a denial of service. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.35.SP1, prior to 2.2.6.SP1, prior to 2.2.7.SP1, prior to 2.0.36.SP1, prior to 2.2.9.Final and prior to 2.0.39.Final.

CVSS3: 5.9
nvd
больше 3 лет назад

A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circumstances, resulting in a denial of service. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.35.SP1, prior to 2.2.6.SP1, prior to 2.2.7.SP1, prior to 2.0.36.SP1, prior to 2.2.9.Final and prior to 2.0.39.Final.

CVSS3: 5.9
debian
больше 3 лет назад

A flaw was found in undertow. The HTTP2SourceChannel fails to write th ...

EPSS

Процентиль: 38%
0.00169
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-362