CVE-2021-3859

HIGH

Undertow - Denial of Service

Title source: llm
STIX 2.1

Description

A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out denial of service attacks.

Scores

CVSS v3 7.5
EPSS 0.0027
EPSS Percentile 50.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-214 CWE-668
Status published
Products (9)
io.undertow/undertow-core 0 - 2.2.15Maven
netapp/cloud_secure_agent
netapp/oncommand_insight
netapp/oncommand_workflow_automation
redhat/jboss_enterprise_application_platform 7.3
redhat/jboss_enterprise_application_platform 7.4
redhat/single_sign-on 7.4.10
redhat/single_sign-on 7.5.1
redhat/undertow < 2.2.15
Published Aug 26, 2022
Tracked Since Feb 18, 2026