Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3690

Опубликовано: 30 июл. 2021
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is availability.

Отчет

Although Red Hat OpenStack Platform packages the vulnerable code in Opendaylight, it does not use or support the undertow-encapsulating features. The security impact for RHOSP is therefore rated as Low and no update will be provided at this time.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of QuarkusundertowNot affected
Red Hat Decision Manager 7undertowNot affected
Red Hat Integration Camel K 1undertowAffected
Red Hat Integration Service RegistryundertowNot affected
Red Hat JBoss Data Grid 7undertowOut of support scope
Red Hat JBoss Fuse 6undertowOut of support scope
Red Hat OpenStack Platform 13 (Queens)undertowWill not fix
Red Hat Process Automation 7undertowNot affected
EAP 7.3.9 releaseFixedRHSA-2021:347108.09.2021
EAP 7.3 asyncFixedRHSA-2021:321618.08.2021

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-401
https://bugzilla.redhat.com/show_bug.cgi?id=1991299undertow: buffer leak on incoming websocket PONG message may lead to DoS

EPSS

Процентиль: 51%
0.00278
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 3 лет назад

A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is availability.

CVSS3: 7.5
nvd
больше 3 лет назад

A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is availability.

CVSS3: 7.5
debian
больше 3 лет назад

A flaw was found in Undertow. A buffer leak on the incoming WebSocket ...

CVSS3: 7.5
github
больше 3 лет назад

Undertow vulnerable to memory exhaustion due to buffer leak

EPSS

Процентиль: 51%
0.00278
Низкий

7.5 High

CVSS3