Description
A flaw was found in Undertow. A potential security issue in flow control handling by the browser over http/2 may potentially cause overhead or a denial of service in the server. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.40.Final and prior to 2.2.11.Final.
References (2)
Core 2
Core References
Issue Tracking, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=1977362
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20220729-0008/
Scores
CVSS v3
5.9
EPSS
0.0029
EPSS Percentile
52.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-400
Status
published
Products (11)
io.undertow/undertow-core
0 - 2.0.40.FinalMaven
netapp/active_iq_unified_manager
(3 CPE variants)
netapp/oncommand_insight
netapp/oncommand_workflow_automation
redhat/integration
redhat/jboss_enterprise_application_platform
redhat/jboss_enterprise_application_platform
7.4
redhat/jboss_enterprise_application_platform
7.3
redhat/single_sign-on
redhat/undertow
< 2.0.40
... and 1 more
Published
May 24, 2022
Tracked Since
Feb 18, 2026