CVE-2021-3597

A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circumstances, resulting in a denial of service. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.35.SP1, prior to 2.2.6.SP1, prior to 2.2.7.SP1, prior to 2.0.36.SP1, prior to 2.2.9.Final and prior to 2.0.39.Final.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:fuse:1.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:-:*:*:*:text-only:*:*:*
cpe:2.3:a:redhat:openshift_application_runtimes:-:*:*:*:text-only:*:*:*
cpe:2.3:a:redhat:single_sign-on:-:*:*:*:text-only:*:*:*
cpe:2.3:a:redhat:undertow:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:undertow:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:undertow:2.0.35:-:*:*:*:*:*:*
cpe:2.3:a:redhat:undertow:2.0.36:-:*:*:*:*:*:*
cpe:2.3:a:redhat:undertow:2.0.39:-:*:*:*:*:*:*
cpe:2.3:a:redhat:undertow:2.2.6:-:*:*:*:*:*:*
cpe:2.3:a:redhat:undertow:2.2.7:-:*:*:*:*:*:*
cpe:2.3:a:redhat:undertow:2.2.9:-:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.3:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.4:*:*:*:*:*:*:*
OR cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*
cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2022-05-24 19:15

Updated : 2024-11-21 06:21


NVD link : CVE-2021-3597

Mitre link : CVE-2021-3597

CVE.ORG link : CVE-2021-3597


JSON object : View

Products Affected

netapp

  • active_iq_unified_manager
  • oncommand_workflow_automation
  • oncommand_insight

redhat

  • fuse
  • openshift_application_runtimes
  • jboss_enterprise_application_platform
  • single_sign-on
  • enterprise_linux
  • undertow
CWE
CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')