CVE-2021-3859

Aliases:GHSA-339q-62wm-c39w
Advisory lineage Upstream: 0 Downstream: 9
Modified
Published: 26 Aug 2022, 00:00
Last modified:03 Aug 2024, 17:09

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
7.5 HIGH
v3.1 (nvd)
EPSS Score
0.32% LOW
0% probability +0.05%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

26 Aug 2022, 00:00
Published
Vulnerability first disclosed
03 Aug 2024, 17:09
Last Modified
Vulnerability information updated

Description

A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out denial of service attacks.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.32% Percentile: 55%

Techniques & Countermeasures

  • CWE-668Exposure of Resource to Wrong Sphere

    The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

  • CWE-214Invocation of Process Using Visible Sensitive Information

    A process is invoked with sensitive command-line arguments, environment variables, or other elements that can be seen by other processes on the operating system.

Affected Systems

  • io.undertowundertow-core

    < 2.2.15

  • netappcloud_secure_agent

    na

  • netapponcommand_insight

    na

  • netapponcommand_workflow_automation

    na

  • redhatjboss_enterprise_application_platform

    7.3 | 7.4

  • redhatsingle_sign-on

    7.4.10 | 7.5.1

  • redhatundertow

    < 2.2.15

References (11)