VYPR
Medium severity5.9NVD Advisory· Published May 24, 2022· Updated Jun 17, 2026

CVE-2021-3629

CVE-2021-3629

Description

A flaw was found in Undertow. A potential security issue in flow control handling by the browser over http/2 may potentially cause overhead or a denial of service in the server. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.40.Final and prior to 2.2.11.Final.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
io.undertow:undertow-coreMaven
< 2.0.40.Final2.0.40.Final
io.undertow:undertow-coreMaven
>= 2.1.0, < 2.2.11.Final2.2.11.Final

Affected products

14
  • cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*+ 2 more
    • cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*
    • cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
    • cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*
  • cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*
  • cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:*
  • cpe:2.3:a:redhat:integration:-:*:*:*:text-only:*:*:*
  • cpe:2.3:a:redhat:jboss_enterprise_application_platform:-:*:*:*:text-only:*:*:*+ 2 more
    • cpe:2.3:a:redhat:jboss_enterprise_application_platform:-:*:*:*:text-only:*:*:*
    • cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.3:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.4:*:*:*:*:*:*:*
  • cpe:2.3:a:redhat:single_sign-on:-:*:*:*:text-only:*:*:*
  • cpe:2.3:a:redhat:undertow:*:*:*:*:*:*:*:*
    Range: <2.0.40
  • cpe:2.3:a:redhat:wildfly_core:*:*:*:*:*:*:*:*
    Range: <17.0
  • Undertow/Undertowdescription
  • ghsa-coords
    Range: < 2.0.40.Final

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.