7.5
CVSSv3

CVE-2022-1259

Published: 31/08/2022 Updated: 07/11/2022
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of service in the server. This flaw exists because of an incomplete fix for CVE-2021-3629.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat jboss enterprise application platform 7.0.0

redhat single sign-on 7.0

redhat openshift application runtimes -

redhat build of quarkus -

redhat integration camel k -

redhat undertow

redhat undertow 2.2.18

redhat undertow 2.2.19

netapp oncommand workflow automation -

netapp oncommand insight -

netapp active iq unified manager -

netapp cloud secure agent -

Vendor Advisories

Debian Bug report logs - #1016448 undertow: CVE-2022-1319 CVE-2021-3629 Package: src:undertow; Maintainer for src:undertow is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Sun, 31 Jul 2022 19:39:02 UTC Severity: grave Tags: security, ups ...
Synopsis Important: Red Hat JBoss Enterprise Application Platform 747 Security update Type/Severity Security Advisory: Important Topic A security update is now available for Red Hat JBoss Enterprise Application Platform 74Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scorin ...
Synopsis Important: Red Hat JBoss Enterprise Application Platform 747 Security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic A security update is now available for Red Hat JBoss Enterprise Application Platform ...
Synopsis Important: Red Hat JBoss Enterprise Application Platform 747 Security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic A security update is now available for Red Hat JBoss Enterprise Application Platform ...
Synopsis Important: Red Hat JBoss Enterprise Application Platform 747 Security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic A security update is now available for Red Hat JBoss Enterprise Application Platform ...
Synopsis Moderate: Red Hat support for Spring Boot 272 update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat OpenShift Application Runtimes Description Red Hat support for Spring Boot provides an application platform that reduces the complexity of developing and operating applications (monoliths an ...
Synopsis Important: Red Hat Fuse 7110 release and security update Type/Severity Security Advisory: Important Topic A minor version update (from 710 to 711) is now available for Red Hat Fuse The purpose of this text-only errata is to inform you about the security issues fixed in this releaseRed Hat Product Security has rated this update ...