VDB

RHSA-2021%3A3218

RHSA-2021%3A3218 PUBLISHED CVSS 7.5 HIGH

A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is availability.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Red Hatorg.jsoup.jsoup-1.8.3.redhat-2.jar as a component of Red Hat JBoss Enterprise Application Platform org.jsoup.jsoup-1.8.3.redhat-2.jar
Red Hatorg.wildfly.security.elytron-web.undertow-server-servlet-1.9.0.Final-redhat-00001.pom as a component of Red Hat JBoss Enterprise Application Platform org.wildfly.security.elytron-web.undertow-server-servlet-1.9.0.Final-redhat-00001.pom
Red HatNone.parse-entities-1.2.2 as a component of Red Hat JBoss Enterprise Application Platform *
Red Hatorg.jboss.eap.wildfly-weld-common-7.4.0.GA-redhat-00005.pom as a component of Red Hat JBoss Enterprise Application Platform org.jboss.eap.wildfly-weld-common-7.4.0.GA-redhat-00005.pom
Red Hatorg.jboss.spec.javax.interceptor.jboss-interceptors-api_1.2_spec-2.0.0.Final-redhat-00002.jar as a component of Red Hat JBoss Enterprise Application Platform org.jboss.spec.javax.interceptor.jboss-interceptors-api_1.2_spec-2.0.0.Final-redhat-00002.jar
Red Hatorg.apache.cxf.cxf-rt-databinding-aegis-3.3.9.redhat-00001.pom as a component of Red Hat JBoss Enterprise Application Platform *
Red HatNone.postcss-reporter-6.0.1 as a component of Red Hat JBoss Enterprise Application Platform None.postcss-reporter-6.0.1
Red Hatorg.wildfly.security.wildfly-elytron-mechanism-digest-1.15.3.Final-redhat-00001.pom as a component of Red Hat JBoss Enterprise Application Platform org.wildfly.security.wildfly-elytron-mechanism-digest-1.15.3.Final-redhat-00001.pom
Red HatNone.is-glob-4.0.1 as a component of Red Hat JBoss Enterprise Application Platform None.is-glob-4.0.1
Red HatNone.get-stdin-4.0.1 as a component of Red Hat JBoss Enterprise Application Platform None.get-stdin-4.0.1
Red HatNone.spdx-correct-3.1.0 as a component of Red Hat JBoss Enterprise Application Platform *
Red Hatorg.apache.activemq.artemis-journal-2.16.0.redhat-00022.jar as a component of Red Hat JBoss Enterprise Application Platform *
Red Hatorg.apache.lucene.lucene-facet-5.5.5.redhat-2.jar as a component of Red Hat JBoss Enterprise Application Platform org.apache.lucene.lucene-facet-5.5.5.redhat-2.jar
Red Hatorg.jboss.eap.wildfly-mail-7.4.0.GA-redhat-00005.pom as a component of Red Hat JBoss Enterprise Application Platform org.jboss.eap.wildfly-mail-7.4.0.GA-redhat-00005.pom
Red Hatio.undertow.undertow-servlet-2.2.5.Final-redhat-00001.pom as a component of Red Hat JBoss Enterprise Application Platform *
Red Hatorg.wildfly.core.wildfly-management-client-content-15.0.2.Final-redhat-00001.pom as a component of Red Hat JBoss Enterprise Application Platform org.wildfly.core.wildfly-management-client-content-15.0.2.Final-redhat-00001.pom
Red HatNone.har-schema-2.0.0 as a component of Red Hat JBoss Enterprise Application Platform None.har-schema-2.0.0
Red Hatorg.jboss.eap.wildfly-ejb3-7.4.0.GA-redhat-00005.pom as a component of Red Hat JBoss Enterprise Application Platform *
Red Hatorg.jboss.eap.wildfly-security-vault-tool-7.4.0.GA-redhat-00005.jar as a component of Red Hat JBoss Enterprise Application Platform *
Red Hat@babel.code-frame-7.0.0 as a component of Red Hat JBoss Enterprise Application Platform @babel.code-frame-7.0.0

…and 2017 more

Timeline

  • Aug 18, 2021 CVE Published
  • Apr 1, 2026 CVE Updated
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›