A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is availability.
[
{
"id": "CVE-2021-3690-45402648",
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 601.0,
"function_hash": "187851407789216287730490246308857511865"
},
"target": {
"function": "onFullPongMessage",
"file": "websockets-jsr/src/main/java/io/undertow/websockets/jsr/FrameHandler.java"
},
"source": "https://github.com/undertow-io/undertow/commit/c7e84a0b7efced38506d7d1dfea5902366973877",
"deprecated": false
},
{
"id": "CVE-2021-3690-e32340ef",
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"line_hashes": [
"79403700335528539273770068144736272793",
"79857656579781679713873665099933085318",
"244125084856819352952595829882912148068",
"137441744319017044843376062865140644092"
],
"threshold": 0.9
},
"target": {
"file": "websockets-jsr/src/main/java/io/undertow/websockets/jsr/FrameHandler.java"
},
"source": "https://github.com/undertow-io/undertow/commit/c7e84a0b7efced38506d7d1dfea5902366973877",
"deprecated": false
}
]