CVE-2021-3690
Vulnerability Summary
Timeline
Description
A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is availability.
CVSS Metrics
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Trends
Current EPSS score: 1.68%• Percentile: 76%
Techniques & Countermeasures
- CWE-400•Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
- CWE-401•Missing Release of Memory after Effective Lifetime
The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.
Affected Systems
- debian•undertow
< 2.2.10-1
- io.undertow•undertow-core
< 2.0.40 | ≥ 2.2.0, < 2.2.10
- redhat•fuse
1.0
- redhat•integration_camel_k
na
- redhat•integration_camel_quarkus
na
- redhat•jboss_enterprise_application_platform
na | 7.3 | 7.4
- redhat•openshift_application_runtimes
na
- redhat•single_sign-on
na
- redhat•undertow
< 2.0.40 | ≥ 2.1.0, < 2.2.10
- redhat•eap7-undertow
< 0:2.0.38-2.SP2_redhat_00001.1.el6eap | < 0:2.0.38-2.SP2_redhat_00001.1.el7eap | < 0:2.0.38-2.SP2_redhat_00001.1.el8eap | < 0:2.2.5-2.SP1_redhat_00001.1.el7eap | < 0:2.2.5-2.SP1_redhat_00001.1.el8eap
References (19)
- https://issues.redhat.com/browse/UNDERTOW-1935
- https://bugzilla.redhat.com/show_bug.cgi?id=1991299
- https://access.redhat.com/security/cve/CVE-2021-3690
- https://github.com/undertow-io/undertow/commit/c7e84a0b7efced38506d7d1dfea5902366973877
- https://nvd.nist.gov/vuln/detail/CVE-2021-3690
- https://access.redhat.com/security/cve/cve-2021-3690#cve-cvss-v3
- https://github.com/undertow-io/undertow
- https://www.mend.io/vulnerability-database/CVE-2021-3690
- https://security-tracker.debian.org/tracker/CVE-2021-3690
- https://access.redhat.com/errata/RHSA-2021:3217
- https://access.redhat.com/security/updates/classification/#important
- https://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.3/
- https://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.3/html-single/installation_guide/
- https://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_3217.json
- https://www.cve.org/CVERecord?id=CVE-2021-3690
- https://access.redhat.com/errata/RHSA-2021:3219
- https://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.4/
- https://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.4/html-single/installation_guide/
- https://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_3219.json