A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is availability.
{ "vanir_signatures": [ { "source": "https://github.com/undertow-io/undertow/commit/c7e84a0b7efced38506d7d1dfea5902366973877", "id": "CVE-2021-3690-45402648", "digest": { "length": 601.0, "function_hash": "187851407789216287730490246308857511865" }, "target": { "file": "websockets-jsr/src/main/java/io/undertow/websockets/jsr/FrameHandler.java", "function": "onFullPongMessage" }, "signature_version": "v1", "deprecated": false, "signature_type": "Function" }, { "source": "https://github.com/undertow-io/undertow/commit/c7e84a0b7efced38506d7d1dfea5902366973877", "id": "CVE-2021-3690-e32340ef", "digest": { "line_hashes": [ "79403700335528539273770068144736272793", "79857656579781679713873665099933085318", "244125084856819352952595829882912148068", "137441744319017044843376062865140644092" ], "threshold": 0.9 }, "target": { "file": "websockets-jsr/src/main/java/io/undertow/websockets/jsr/FrameHandler.java" }, "signature_version": "v1", "deprecated": false, "signature_type": "Line" } ] }