The vendor explicitly identifies these products as affected by this CVE.
- undertow as a component of Red Hat build of Quarkus
- undertow as a component of Red Hat Integration Camel K 1
- undertow as a component of Red Hat Integration Service Registry
- undertow as a component of Red Hat JBoss Data Grid 7
- undertow as a component of Red Hat JBoss Fuse 6
- opendaylight as a component of Red Hat OpenStack Platform 13 (Queens)
- opendaylight.src as a component of Red Hat OpenStack Platform 13 (Queens)
- undertow as a component of Red Hat Single Sign-On 7
- Summary
- A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of service in the server.
- Remediation
- Before applying this update, ensure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database settings. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
