A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circumstances, resulting in a denial of service. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.35.SP1, prior to 2.2.6.SP1, prior to 2.2.7.SP1, prior to 2.0.36.SP1, prior to 2.2.9.Final and prior to 2.0.39.Final.
References
Link Resource
https://bugzilla.redhat.com/show_bug.cgi?id=1970930 Issue Tracking Third Party Advisory
https://security.netapp.com/advisory/ntap-20220804-0003/ Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2022-05-24T18:19:11

Updated: 2022-08-04T17:06:48

Reserved: 2021-06-11T00:00:00


Link: CVE-2021-3597

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-05-24T19:15:09.037

Modified: 2022-11-10T16:43:28.037


Link: CVE-2021-3597

JSON object: View

cve-icon Redhat Information

No data.

CWE