Описание
A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in a loop, generating new connections which are not properly closed while not able to connect to domain-controller. This flaw allows an attacker to cause an Out of memory (OOM) issue, leading to a denial of service. The highest threat from this vulnerability is to system availability.
A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where the host-controller tries to reconnect in a loop, generating new connections that are not properly closed while unable to connect to the domain controller. This flaw allows an attacker to cause an Out of memory (OOM) issue, leading to a denial of service. The highest threat from this vulnerability is to system availability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat CodeReady Studio 12 | wildfly-core | Not affected | ||
| Red Hat Decision Manager 7 | wildfly-core | Not affected | ||
| Red Hat JBoss Data Grid 7 | wildfly-core | Out of support scope | ||
| Red Hat JBoss Fuse 6 | wildfly-core | Out of support scope | ||
| Red Hat OpenShift Application Runtimes | wildfly-core | Affected | ||
| Red Hat Process Automation 7 | wildfly-core | Not affected | ||
| Red Hat Fuse 7.11 | wildfly-core | Fixed | RHSA-2022:5532 | 07.07.2022 |
| Red Hat JBoss Enterprise Application Platform 7 | wildfly-core | Fixed | RHSA-2021:0250 | 25.01.2021 |
| Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6 | eap7-activemq-artemis | Fixed | RHSA-2021:0246 | 25.01.2021 |
| Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6 | eap7-glassfish-jsf | Fixed | RHSA-2021:0246 | 25.01.2021 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in a loop, generating new connections which are not properly closed while not able to connect to domain-controller. This flaw allows an attacker to cause an Out of memory (OOM) issue, leading to a denial of service. The highest threat from this vulnerability is to system availability.
A memory leak flaw was found in WildFly in all versions up to 21.0.0.F ...
EPSS
5.3 Medium
CVSS3