Lucene search

K
cvelistRedhatCVELIST:CVE-2021-3597
HistoryMay 24, 2022 - 6:19 p.m.

CVE-2021-3597

2022-05-2418:19:11
CWE-362
redhat
www.cve.org
1

6.4 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

39.4%

A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circumstances, resulting in a denial of service. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.35.SP1, prior to 2.2.6.SP1, prior to 2.2.7.SP1, prior to 2.0.36.SP1, prior to 2.2.9.Final and prior to 2.0.39.Final.

CNA Affected

[
  {
    "product": "undertow",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "undertow 2.0.35.SP1, undertow 2.2.6.SP1, undertow 2.2.7.SP1, undertow 2.0.36.SP1, undertow 2.2.9.Final, undertow 2.0.39.Final"
      }
    ]
  }
]

6.4 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

39.4%