CVE-2021-3629

MEDIUM

Redhat Integration < 2.0.40 - Denial of Service

Title source: rule
STIX 2.1

Description

A flaw was found in Undertow. A potential security issue in flow control handling by the browser over http/2 may potentially cause overhead or a denial of service in the server. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.40.Final and prior to 2.2.11.Final.

References (2)

Core 2
Core References
Issue Tracking, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=1977362
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20220729-0008/

Scores

CVSS v3 5.9
EPSS 0.0029
EPSS Percentile 52.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-400
Status published
Products (11)
io.undertow/undertow-core 0 - 2.0.40.FinalMaven
netapp/active_iq_unified_manager (3 CPE variants)
netapp/oncommand_insight
netapp/oncommand_workflow_automation
redhat/integration
redhat/jboss_enterprise_application_platform
redhat/jboss_enterprise_application_platform 7.4
redhat/jboss_enterprise_application_platform 7.3
redhat/single_sign-on
redhat/undertow < 2.0.40
... and 1 more
Published May 24, 2022
Tracked Since Feb 18, 2026