CVE-2021-3859
Summary
| CVE | CVE-2021-3859 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-08-26 16:15:00 UTC |
| Updated | 2022-12-13 02:25:00 UTC |
| Description | A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out denial of service attacks. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| CVE-2021-3859 Undertow Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| [UNDERTOW-1979] CVE-2021-3859 Continuation frames are not read correctly - Red Hat Issue Tracker |
MISC |
issues.redhat.com |
|
| Red Hat Customer Portal - Access to 24x7 support and knowledge |
MISC |
access.redhat.com |
|
| [UNDERTOW-1979] CVE-2021-3859 continuation frames are not read correctly by fl4via · Pull Request #1296 · undertow-io/undertow · GitHub |
MISC |
github.com |
|
| 2010378 – (CVE-2021-3859) CVE-2021-3859 undertow: client side invocation timeout raised when calling over HTTP2 |
MISC |
bugzilla.redhat.com |
|
| [UNDERTOW-1979] CVE-2021-3859 continuation frames are not read correctly · undertow-io/undertow@e43f0ad · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 240056 Red Hat Update for JBoss Enterprise Application Platform 7.4.3 (RHSA-2022:0401)
- 240057 Red Hat Update for JBoss Enterprise Application Platform 7.3 (RHSA-2022:0405)
- 240058 Red Hat Update for JBoss Enterprise Application Platform 7.4.3 (RHSA-2022:0400)