undertow Race Condition vulnerability
Moderate severity
GitHub Reviewed
Published
May 25, 2022
to the GitHub Advisory Database
•
Updated Jan 31, 2023
Package
Affected versions
>= 2.1.0, <= 2.2.8.Final
<= 2.0.38.Final
Patched versions
2.2.9.Final
2.0.39.Final
Description
Published by the National Vulnerability Database
May 24, 2022
Published to the GitHub Advisory Database
May 25, 2022
Reviewed
May 25, 2022
Last updated
Jan 31, 2023
A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circumstances, resulting in a denial of service. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.35.SP1, prior to 2.2.6.SP1, prior to 2.2.7.SP1, prior to 2.0.36.SP1, prior to 2.2.9.Final and prior to 2.0.39.Final.
References