Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rf6q-vx79-mjxr

Опубликовано: 25 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Undertow Uncontrolled Resource Consumption

A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may potentially cause overhead or a denial of service in the server. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.40.Final and prior to 2.2.11.Final.

Пакеты

Наименование

io.undertow:undertow-core

maven
Затронутые версииВерсия исправления

<= 2.0.39.Final

2.0.40.Final

Наименование

io.undertow:undertow-core

maven
Затронутые версииВерсия исправления

>= 2.1.0, <= 2.2.10.Final

2.2.11.Final

EPSS

Процентиль: 58%
0.00358
Низкий

7.5 High

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 3 лет назад

A flaw was found in Undertow. A potential security issue in flow control handling by the browser over http/2 may potentially cause overhead or a denial of service in the server. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.40.Final and prior to 2.2.11.Final.

CVSS3: 5.9
redhat
почти 5 лет назад

A flaw was found in Undertow. A potential security issue in flow control handling by the browser over http/2 may potentially cause overhead or a denial of service in the server. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.40.Final and prior to 2.2.11.Final.

CVSS3: 5.9
nvd
больше 3 лет назад

A flaw was found in Undertow. A potential security issue in flow control handling by the browser over http/2 may potentially cause overhead or a denial of service in the server. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.40.Final and prior to 2.2.11.Final.

CVSS3: 5.9
debian
больше 3 лет назад

A flaw was found in Undertow. A potential security issue in flow contr ...

EPSS

Процентиль: 58%
0.00358
Низкий

7.5 High

CVSS3

Дефекты

CWE-400