A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out denial of service attacks.
{ "vanir_signatures": [ { "id": "CVE-2021-3859-137c9e03", "digest": { "line_hashes": [ "37843366493750751742619379260952401598", "7440480657494467487553469539626601166", "276016304061374303955031587394107556688", "33025093169843178057269548979765714246", "73007699941547598036833828651447045206", "281097977987362871672003164118742789719", "219130153540905508636829466680708263762", "15958409315759019669908654030384320735" ], "threshold": 0.9 }, "source": "https://github.com/undertow-io/undertow/commit/e43f0ada3f4da6e8579e0020cec3cb1a81e487c2", "target": { "file": "core/src/main/java/io/undertow/protocols/http2/HpackEncoder.java" }, "signature_version": "v1", "deprecated": false, "signature_type": "Line" }, { "id": "CVE-2021-3859-80ae0061", "digest": { "line_hashes": [ "278718351439749032103358072259880297915", "217996040743920694930878954795178553663", "194636829920015321065860618077163562720", "272077580847901113784842885408509213057", "335496155086488876403469198514903259863", "93657172332355147865052391949714358868", "10177502587792283635465765649640402178", "6822285975597295230959649532656960108", "2961991051668216914488364019458986316", "271247688705289436524263595311819397500" ], "threshold": 0.9 }, "source": "https://github.com/undertow-io/undertow/commit/e43f0ada3f4da6e8579e0020cec3cb1a81e487c2", "target": { "file": "core/src/main/java/io/undertow/protocols/http2/Http2Channel.java" }, "signature_version": "v1", "deprecated": false, "signature_type": "Line" }, { "id": "CVE-2021-3859-a100b2a7", "digest": { "length": 2626.0, "function_hash": "197540148066880075987836166995993802539" }, "source": "https://github.com/undertow-io/undertow/commit/e43f0ada3f4da6e8579e0020cec3cb1a81e487c2", "target": { "function": "encode", "file": "core/src/main/java/io/undertow/protocols/http2/HpackEncoder.java" }, "signature_version": "v1", "deprecated": false, "signature_type": "Function" }, { "id": "CVE-2021-3859-b0ceb238", "digest": { "length": 1089.0, "function_hash": "291203542927830118324038302489004741089" }, "source": "https://github.com/undertow-io/undertow/commit/e43f0ada3f4da6e8579e0020cec3cb1a81e487c2", "target": { "function": "parseFrame", "file": "core/src/main/java/io/undertow/protocols/http2/Http2Channel.java" }, "signature_version": "v1", "deprecated": false, "signature_type": "Function" } ] }