Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-1259

Опубликовано: 06 апр. 2022
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of service in the server. This flaw exists because of an incomplete fix for CVE-2021-3629.

A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of service in the server.

Отчет

This flaw occurs because of an incomplete fix for CVE-2021-3629.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of QuarkusundertowWill not fix
Red Hat Decision Manager 7undertowNot affected
Red Hat Integration Camel K 1undertowFix deferred
Red Hat Integration Camel Quarkus 1undertowFix deferred
Red Hat Integration Service RegistryundertowFix deferred
Red Hat JBoss Data Grid 7undertowOut of support scope
Red Hat JBoss Enterprise Application Platform Expansion PackundertowNot affected
Red Hat JBoss Fuse 6undertowOut of support scope
Red Hat OpenStack Platform 13 (Queens)opendaylightOut of support scope
Red Hat Process Automation 7undertowNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400->CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2072339undertow: potential security issue in flow control over HTTP/2 may lead to DOS(incomplete fix for CVE-2021-3629)

EPSS

Процентиль: 47%
0.0024
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 3 лет назад

A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of service in the server. This flaw exists because of an incomplete fix for CVE-2021-3629.

CVSS3: 7.5
nvd
больше 3 лет назад

A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of service in the server. This flaw exists because of an incomplete fix for CVE-2021-3629.

CVSS3: 7.5
debian
больше 3 лет назад

A flaw was found in Undertow. A potential security issue in flow contr ...

CVSS3: 7.5
github
больше 3 лет назад

A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of service in the server. This flaw exists because of an incomplete fix for CVE-2021-3629.

EPSS

Процентиль: 47%
0.0024
Низкий

7.5 High

CVSS3