Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-25644

Опубликовано: 22 сент. 2020
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM leading to a denial of service. The highest threat from this vulnerability is to system availability.

A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. This flaw allows an attacker to cause an Out of memory (OOM) issue, leading to a denial of service. The highest threat from this vulnerability is to system availability.

Меры по смягчению последствий

There is currently no known mitigation for this issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Decision Manager 7wildfly-opensslNot affected
Red Hat OpenShift Application Runtimeswildfly-opensslAffected
Red Hat Process Automation 7wildfly-opensslNot affected
EAP 7.3.3wildfly-openssl-natives-parentFixedRHSA-2020:492304.11.2020
Red Hat Data Grid 7.3.8wildfly-opensslFixedRHSA-2020:541014.12.2020
Red Hat Data Grid 8.1.1wildfly-opensslFixedRHSA-2021:043308.02.2021
Red Hat Fuse 7.9wildfly-opensslFixedRHSA-2021:314011.08.2021
Red Hat JBoss Enterprise Application Platform 7wildfly-openssl-natives-parentFixedRHSA-2020:425714.10.2020
Red Hat JBoss Enterprise Application Platform 7FixedRHSA-2020:534403.12.2020
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7eap7-glassfish-elFixedRHSA-2025:958225.06.2025

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-401
https://bugzilla.redhat.com/show_bug.cgi?id=1885485wildfly-openssl: memory leak per HTTP session creation in WildFly OpenSSL

EPSS

Процентиль: 64%
0.00465
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 5 лет назад

A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM leading to a denial of service. The highest threat from this vulnerability is to system availability.

CVSS3: 7.5
debian
больше 5 лет назад

A memory leak flaw was found in WildFly OpenSSL in versions prior to 1 ...

CVSS3: 7.5
github
больше 3 лет назад

Wildfly-OpenSSL memory leak flaw

CVSS3: 7.5
fstec
больше 5 лет назад

Уязвимость библиотеки OpenSSL сервера WildFly, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании или получить полный доступ к системе

EPSS

Процентиль: 64%
0.00465
Низкий

7.5 High

CVSS3

Уязвимость CVE-2020-25644