#VU60243 Resource management error in Undertow - CVE-2021-3859
Published: February 2, 2022 / Updated: February 3, 2022
Undertow
Red Hat Inc.
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper handling of client side invocation timeout within the application when handling HTTP/2 requests. A remote attacker can send specially crafted requests to the application and perform a denial of service (DoS) attack.