PT-2022-10597 · Undertow · Undertow

Andrew Marinchuk

·

Published

2022-07-15

·

Updated

2024-11-08

·

CVE-2021-3690

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Undertow versions prior to 2.0.40 Undertow versions prior to 2.2.10
Description A flaw was found in Undertow, where a buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion, allowing an attacker to cause a denial of service. The highest threat from this issue is availability.
Recommendations For Undertow versions prior to 2.0.40, update to version 2.0.40 or later to resolve the issue. For Undertow versions prior to 2.2.10, update to version 2.2.10 or later to resolve the issue. As a temporary workaround, consider restricting access to WebSocket PONG messages to minimize the risk of exploitation.

Exploit

Fix

DoS

Memory Leak

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-3690
GHSA-FJ7C-VG2V-CCRM
OESA-2024-2353
RHSA-2021:3217
RHSA-2021:3219
RHSA-2021:3466
RHSA-2021:3467
RHSA-2021:3468
RHSA-2021:3656
RHSA-2021:3658
RHSA-2025:4226

Affected Products

Undertow