Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. io.undertow/undertow-core
  4. ›
  5. CVE-2021-3597

CVE-2021-3597: Race condition in undertow

May 24, 2022 (updated November 10, 2022)

A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circumstances, resulting in a denial of service. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.35.SP1, prior to 2.2.6.SP1, prior to 2.2.7.SP1, prior to 2.0.36.SP1, prior to 2.2.9.Final and prior to 2.0.39.Final.

References

  • bugzilla.redhat.com/show_bug.cgi?id=1970930
  • github.com/advisories/GHSA-mfhv-gwf8-4m88
  • nvd.nist.gov/vuln/detail/CVE-2021-3597

Code Behaviors & Features

Detect and mitigate CVE-2021-3597 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions up to 2.0.38.final, all versions starting from 2.1.0 up to 2.2.8.final

Fixed versions

  • 2.0.39.Final
  • 2.2.9.Final

Solution

Upgrade to versions 2.0.39.Final, 2.2.9.Final or above.

Impact 5.9 MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Learn more about CVSS

Weakness

  • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Source file

maven/io.undertow/undertow-core/CVE-2021-3597.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:16:09 +0000.