You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A flaw was found in Undertow. A potential security issue in flow control handling by the browser over http/2 may potentially cause overhead or a denial of service in the server. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.40.Final and prior to 2.2.11.Final.
CVE-2021-3629 - Medium Severity Vulnerability
Vulnerable Library - undertow-core-2.0.15.Final.jar
Undertow
Path to dependency file: /t/sub1/pom.xml
Path to vulnerable library: /2/repository/io/undertow/undertow-core/2.0.15.Final/undertow-core-2.0.15.Final.jar
Dependency Hierarchy:
Found in HEAD commit: 37c7d89138d443bae9926a0184046f8d8c7dda51
Found in base branch: master
Vulnerability Details
A flaw was found in Undertow. A potential security issue in flow control handling by the browser over http/2 may potentially cause overhead or a denial of service in the server. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.40.Final and prior to 2.2.11.Final.
Publish Date: 2022-05-24
URL: CVE-2021-3629
CVSS 3 Score Details (5.9)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://www.cve.org/CVERecord?id=CVE-2021-3629
Release Date: 2022-05-24
Fix Resolution: io.undertow:undertow-core:2.0.40.Final,2.2.11.Final;io.undertow:undertow-benchmarks:2.0.40.Final,2.2.11.Final;io.undertow:undertow-examples:2.0.40.Final,2.2.11.Final
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: