Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-30129

Опубликовано: 12 июл. 2021
Источник: redhat
CVSS3: 6.5

Описание

A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error. This issue affects the SFTP and port forwarding features of Apache Mina SSHD version 2.0.0 and later versions. It was addressed in Apache Mina SSHD 2.7.0

Отчет

Red Hat OpenStack Platform's OpenDaylight will not be updated for this flaw because it was deprecated as of OpenStack Platform 14 and is only receiving security fixes for Critical flaws.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6sshd-coreOut of support scope
Red Hat build of Quarkussshd-commonNot affected
Red Hat CodeReady Studio 12org.apache.sshd.sftpWill not fix
Red Hat Integration Camel K 1sshd-sftpAffected
Red Hat JBoss A-MQ 6sshd-coreOut of support scope
Red Hat JBoss BRMS 6sshd-coreOut of support scope
Red Hat JBoss Fuse 6sshd-coreOut of support scope
Red Hat OpenStack Platform 10 (Newton)opendaylightOut of support scope
Red Hat OpenStack Platform 13 (Queens)opendaylightOut of support scope
EAP 7.4.2 releasesshd-coreFixedRHSA-2021:467915.11.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1981527mina-sshd-core: Memory leak denial of service in Apache Mina SSHD Server

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
больше 4 лет назад

A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error. This issue affects the SFTP and port forwarding features of Apache Mina SSHD version 2.0.0 and later versions. It was addressed in Apache Mina SSHD 2.7.0

CVSS3: 6.5
debian
больше 4 лет назад

A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to ...

CVSS3: 7.5
github
больше 4 лет назад

Buffer Overflow in Apache Mina SSHD

CVSS3: 7.5
fstec
больше 4 лет назад

Уязвимость компонента sshd-core java-библиотеки для поддержки SSH-протоколов Apache SSHD, позволяющая нарушителю вызвать отказ в обслуживании

6.5 Medium

CVSS3