VDB
RHSA-2021%3A3218
RHSA-2021%3A3218
PUBLISHED
CVSS 7.5 HIGH
A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is availability.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | org.jsoup.jsoup-1.8.3.redhat-2.jar as a component of Red Hat JBoss Enterprise Application Platform | org.jsoup.jsoup-1.8.3.redhat-2.jar |
| Red Hat | org.wildfly.security.elytron-web.undertow-server-servlet-1.9.0.Final-redhat-00001.pom as a component of Red Hat JBoss Enterprise Application Platform | org.wildfly.security.elytron-web.undertow-server-servlet-1.9.0.Final-redhat-00001.pom |
| Red Hat | None.parse-entities-1.2.2 as a component of Red Hat JBoss Enterprise Application Platform | * |
| Red Hat | org.jboss.eap.wildfly-weld-common-7.4.0.GA-redhat-00005.pom as a component of Red Hat JBoss Enterprise Application Platform | org.jboss.eap.wildfly-weld-common-7.4.0.GA-redhat-00005.pom |
| Red Hat | org.jboss.spec.javax.interceptor.jboss-interceptors-api_1.2_spec-2.0.0.Final-redhat-00002.jar as a component of Red Hat JBoss Enterprise Application Platform | org.jboss.spec.javax.interceptor.jboss-interceptors-api_1.2_spec-2.0.0.Final-redhat-00002.jar |
| Red Hat | org.apache.cxf.cxf-rt-databinding-aegis-3.3.9.redhat-00001.pom as a component of Red Hat JBoss Enterprise Application Platform | * |
| Red Hat | None.postcss-reporter-6.0.1 as a component of Red Hat JBoss Enterprise Application Platform | None.postcss-reporter-6.0.1 |
| Red Hat | org.wildfly.security.wildfly-elytron-mechanism-digest-1.15.3.Final-redhat-00001.pom as a component of Red Hat JBoss Enterprise Application Platform | org.wildfly.security.wildfly-elytron-mechanism-digest-1.15.3.Final-redhat-00001.pom |
| Red Hat | None.is-glob-4.0.1 as a component of Red Hat JBoss Enterprise Application Platform | None.is-glob-4.0.1 |
| Red Hat | None.get-stdin-4.0.1 as a component of Red Hat JBoss Enterprise Application Platform | None.get-stdin-4.0.1 |
| Red Hat | None.spdx-correct-3.1.0 as a component of Red Hat JBoss Enterprise Application Platform | * |
| Red Hat | org.apache.activemq.artemis-journal-2.16.0.redhat-00022.jar as a component of Red Hat JBoss Enterprise Application Platform | * |
| Red Hat | org.apache.lucene.lucene-facet-5.5.5.redhat-2.jar as a component of Red Hat JBoss Enterprise Application Platform | org.apache.lucene.lucene-facet-5.5.5.redhat-2.jar |
| Red Hat | org.jboss.eap.wildfly-mail-7.4.0.GA-redhat-00005.pom as a component of Red Hat JBoss Enterprise Application Platform | org.jboss.eap.wildfly-mail-7.4.0.GA-redhat-00005.pom |
| Red Hat | io.undertow.undertow-servlet-2.2.5.Final-redhat-00001.pom as a component of Red Hat JBoss Enterprise Application Platform | * |
| Red Hat | org.wildfly.core.wildfly-management-client-content-15.0.2.Final-redhat-00001.pom as a component of Red Hat JBoss Enterprise Application Platform | org.wildfly.core.wildfly-management-client-content-15.0.2.Final-redhat-00001.pom |
| Red Hat | None.har-schema-2.0.0 as a component of Red Hat JBoss Enterprise Application Platform | None.har-schema-2.0.0 |
| Red Hat | org.jboss.eap.wildfly-ejb3-7.4.0.GA-redhat-00005.pom as a component of Red Hat JBoss Enterprise Application Platform | * |
| Red Hat | org.jboss.eap.wildfly-security-vault-tool-7.4.0.GA-redhat-00005.jar as a component of Red Hat JBoss Enterprise Application Platform | * |
| Red Hat | @babel.code-frame-7.0.0 as a component of Red Hat JBoss Enterprise Application Platform | @babel.code-frame-7.0.0 |
…and 2017 more
Timeline
- Aug 18, 2021 CVE Published
- Apr 1, 2026 CVE Updated
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2021:3218 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=securityPatches&product=appplatform&version=7.4 advisory
- https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.4 advisory
- https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.4/html-single/installation_guide/index advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1991299 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_3218.json advisory
- https://access.redhat.com/security/cve/CVE-2021-3690 advisory
- https://www.cve.org/CVERecord?id=CVE-2021-3690 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-3690 advisory