Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3859

Опубликовано: 01 фев. 2022
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out denial of service attacks.

Отчет

Red Hat OpenStack Platform's OpenDaylight will not be updated for this flaw because it was deprecated as of OpenStack Platform 14 and is only receiving security fixes for Critical flaws.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of QuarkusundertowNot affected
Red Hat Decision Manager 7undertowNot affected
Red Hat Integration Camel K 1undertowNot affected
Red Hat Integration Camel Quarkus 1undertowNot affected
Red Hat Integration Service RegistryundertowNot affected
Red Hat JBoss Data Grid 7undertowOut of support scope
Red Hat JBoss Enterprise Application Platform Expansion PackundertowNot affected
Red Hat JBoss Fuse 6undertowOut of support scope
Red Hat OpenStack Platform 10 (Newton)opendaylightOut of support scope
Red Hat OpenStack Platform 13 (Queens)opendaylightOut of support scope

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-214
https://bugzilla.redhat.com/show_bug.cgi?id=2010378undertow: client side invocation timeout raised when calling over HTTP2

EPSS

Процентиль: 50%
0.00273
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 3 лет назад

A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out denial of service attacks.

CVSS3: 7.5
nvd
больше 3 лет назад

A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out denial of service attacks.

CVSS3: 7.5
debian
больше 3 лет назад

A flaw was found in Undertow that tripped the client-side invocation t ...

CVSS3: 7.5
github
больше 3 лет назад

Undertow vulnerable to Denial of Service (DoS) attacks

EPSS

Процентиль: 50%
0.00273
Низкий

7.5 High

CVSS3