CVE-2021-42340
DoS via memory leak with WebSocket connections
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a memory leak that, over time, could lead to a denial of service via an OutOfMemoryError.
La corrección del bug 63362 presente en Apache Tomcat versiones 10.1.0-M1 hasta 10.1.0-M5, versiones 10.0.0-M1 hasta 10.0.11, versiones 9.0.40 hasta 9.0.53 y versiones 8.5.60 hasta 8.5.71, introducía una pérdida de memoria. El objeto introducido para recopilar métricas para las conexiones de actualización HTTP no se liberaba para las conexiones WebSocket una vez que se cerraba la conexión. Esto creaba una pérdida de memoria que, con el tiempo, podía conllevar a una denegación de servicio por medio de un OutOfMemoryError
A memory leak flaw was found in Apache Tomcat, where an HTTP upgrade connection does not release for WebSocket connections once the WebSocket connection is closed. If a sufficient number of such requests are made, an OutOfMemoryError occurs, leading to a denial of service. The highest threat from this vulnerability is to system availability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-10-13 CVE Reserved
- 2021-10-14 CVE Published
- 2024-06-29 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-772: Missing Release of Resource after Effective Lifetime
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
https://kc.mcafee.com/corporate/index?page=content&id=SB10379 | Third Party Advisory | |
https://lists.apache.org/thread.html/r8097a2d1550aa78e585fc77e602b9046e6d4099d8d132497c5387784%40%3Ccommits.myfaces.apache.org%3E | Mailing List | |
https://security.netapp.com/advisory/ntap-20211104-0001 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.oracle.com/security-alerts/cpuapr2022.html | 2023-11-07 | |
https://www.oracle.com/security-alerts/cpujan2022.html | 2023-11-07 | |
https://www.oracle.com/security-alerts/cpujul2022.html | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | >= 8.5.60 < 8.5.72 Search vendor "Apache" for product "Tomcat" and version " >= 8.5.60 < 8.5.72" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | >= 9.0.40 < 9.0.54 Search vendor "Apache" for product "Tomcat" and version " >= 9.0.40 < 9.0.54" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | >= 10.0.1 < 10.0.12 Search vendor "Apache" for product "Tomcat" and version " >= 10.0.1 < 10.0.12" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 10.0.0 Search vendor "Apache" for product "Tomcat" and version "10.0.0" | milestone10 |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 10.1.0 Search vendor "Apache" for product "Tomcat" and version "10.1.0" | milestone1 |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 10.1.0 Search vendor "Apache" for product "Tomcat" and version "10.1.0" | milestone2 |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 10.1.0 Search vendor "Apache" for product "Tomcat" and version "10.1.0" | milestone3 |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 10.1.0 Search vendor "Apache" for product "Tomcat" and version "10.1.0" | milestone4 |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Search vendor "Apache" for product "Tomcat" | 10.1.0 Search vendor "Apache" for product "Tomcat" and version "10.1.0" | milestone5 |
Affected
| ||||||
Netapp Search vendor "Netapp" | Hci Search vendor "Netapp" for product "Hci" | - | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Management Services For Element Software Search vendor "Netapp" for product "Management Services For Element Software" | - | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 11.0 Search vendor "Debian" for product "Debian Linux" and version "11.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Agile Engineering Data Management Search vendor "Oracle" for product "Agile Engineering Data Management" | 6.2.1.0 Search vendor "Oracle" for product "Agile Engineering Data Management" and version "6.2.1.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Big Data Spatial And Graph Search vendor "Oracle" for product "Big Data Spatial And Graph" | < 23.1 Search vendor "Oracle" for product "Big Data Spatial And Graph" and version " < 23.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Diameter Signaling Router Search vendor "Oracle" for product "Communications Diameter Signaling Router" | >= 8.0.0.0 <= 8.5.0.2 Search vendor "Oracle" for product "Communications Diameter Signaling Router" and version " >= 8.0.0.0 <= 8.5.0.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Hospitality Cruise Shipboard Property Management System Search vendor "Oracle" for product "Hospitality Cruise Shipboard Property Management System" | 20.1.0 Search vendor "Oracle" for product "Hospitality Cruise Shipboard Property Management System" and version "20.1.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Managed File Transfer Search vendor "Oracle" for product "Managed File Transfer" | 12.2.1.3.0 Search vendor "Oracle" for product "Managed File Transfer" and version "12.2.1.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Managed File Transfer Search vendor "Oracle" for product "Managed File Transfer" | 12.2.1.4.0 Search vendor "Oracle" for product "Managed File Transfer" and version "12.2.1.4.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Middleware Common Libraries And Tools Search vendor "Oracle" for product "Middleware Common Libraries And Tools" | 12.2.1.4.0 Search vendor "Oracle" for product "Middleware Common Libraries And Tools" and version "12.2.1.4.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Payment Interface Search vendor "Oracle" for product "Payment Interface" | 19.1 Search vendor "Oracle" for product "Payment Interface" and version "19.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Payment Interface Search vendor "Oracle" for product "Payment Interface" | 20.3 Search vendor "Oracle" for product "Payment Interface" and version "20.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Customer Insights Search vendor "Oracle" for product "Retail Customer Insights" | 15.0.2 Search vendor "Oracle" for product "Retail Customer Insights" and version "15.0.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Customer Insights Search vendor "Oracle" for product "Retail Customer Insights" | 16.0.2 Search vendor "Oracle" for product "Retail Customer Insights" and version "16.0.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Data Extractor For Merchandising Search vendor "Oracle" for product "Retail Data Extractor For Merchandising" | 15.0.2 Search vendor "Oracle" for product "Retail Data Extractor For Merchandising" and version "15.0.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Data Extractor For Merchandising Search vendor "Oracle" for product "Retail Data Extractor For Merchandising" | 16.0.2 Search vendor "Oracle" for product "Retail Data Extractor For Merchandising" and version "16.0.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Eftlink Search vendor "Oracle" for product "Retail Eftlink" | 21.0.0 Search vendor "Oracle" for product "Retail Eftlink" and version "21.0.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Financial Integration Search vendor "Oracle" for product "Retail Financial Integration" | 16.0.1 Search vendor "Oracle" for product "Retail Financial Integration" and version "16.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Financial Integration Search vendor "Oracle" for product "Retail Financial Integration" | 19.0.0 Search vendor "Oracle" for product "Retail Financial Integration" and version "19.0.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Store Inventory Management Search vendor "Oracle" for product "Retail Store Inventory Management" | 14.0.4.13 Search vendor "Oracle" for product "Retail Store Inventory Management" and version "14.0.4.13" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Store Inventory Management Search vendor "Oracle" for product "Retail Store Inventory Management" | 14.1.3.5 Search vendor "Oracle" for product "Retail Store Inventory Management" and version "14.1.3.5" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Store Inventory Management Search vendor "Oracle" for product "Retail Store Inventory Management" | 14.1.3.14 Search vendor "Oracle" for product "Retail Store Inventory Management" and version "14.1.3.14" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Store Inventory Management Search vendor "Oracle" for product "Retail Store Inventory Management" | 15.0.3.3 Search vendor "Oracle" for product "Retail Store Inventory Management" and version "15.0.3.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Store Inventory Management Search vendor "Oracle" for product "Retail Store Inventory Management" | 15.0.3.8 Search vendor "Oracle" for product "Retail Store Inventory Management" and version "15.0.3.8" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Retail Store Inventory Management Search vendor "Oracle" for product "Retail Store Inventory Management" | 16.0.3.7 Search vendor "Oracle" for product "Retail Store Inventory Management" and version "16.0.3.7" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Sd-wan Edge Search vendor "Oracle" for product "Sd-wan Edge" | 9.0 Search vendor "Oracle" for product "Sd-wan Edge" and version "9.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Sd-wan Edge Search vendor "Oracle" for product "Sd-wan Edge" | 9.1 Search vendor "Oracle" for product "Sd-wan Edge" and version "9.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Taleo Platform Search vendor "Oracle" for product "Taleo Platform" | * | - |
Affected
|