Skip to main content

Exposure of Resource to Wrong Sphere in io.undertow:undertow-core

CVE-2021-3859

  • io.undertow:undertow-core
Severity High
Score 7.5/10

Summary

A flaw was found in Undertow versions prior to 2.2.15.Final, that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out denial of service attacks.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • NONE
  • HIGH

CWE-668 - Exposure of Resource to Wrong Sphere

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

Advisory Timeline

  • Published