CVE-2021-3859: High severity jboss enterprise application platform vulnerability
A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out denial of service attacks.
Other sources
Invocation of an EJB is failing on the client side with the invocation-timeout being hit.
Reference: https://issues.redhat.com/browse/EAPSUP-651
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-3859?
CVE-2021-3859 is a vulnerability found in Undertow that allows an attacker to carry out denial of service attacks.
What is the severity of CVE-2021-3859?
The severity of CVE-2021-3859 is high, with a severity value of 7.5.
Which software is affected by CVE-2021-3859?
The software affected by CVE-2021-3859 includes Redhat Jboss Enterprise Application Platform versions 7.3 and 7.4, Redhat Single Sign-on versions 7.4.10 and 7.5.1, and Redhat Undertow up to version 2.2.15.
How can I fix CVE-2021-3859?
To fix CVE-2021-3859, update the affected software to the appropriate version provided by Redhat.
Where can I find more information about CVE-2021-3859?
More information about CVE-2021-3859 can be found on the CVE website, the NIST NVD website, the Redhat Bugzilla website, and the Redhat Access website.