Lucene search

K
cvelistRedhatCVELIST:CVE-2021-3629
HistoryMay 24, 2022 - 6:19 p.m.

CVE-2021-3629

2022-05-2418:19:00
CWE-400
redhat
www.cve.org
6
undertow
security flaw
http/2

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

39.2%

A flaw was found in Undertow. A potential security issue in flow control handling by the browser over http/2 may potentially cause overhead or a denial of service in the server. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.40.Final and prior to 2.2.11.Final.

CNA Affected

[
  {
    "product": "undertow",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "undertow 2.0.40.Final, undertow 2.2.11.Final"
      }
    ]
  }
]

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

39.2%