CVE-2021-42340
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/10/2021
Last modified:
07/11/2023
Description
The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a memory leak that, over time, could lead to a denial of service via an OutOfMemoryError.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | 8.5.60 (including) | 8.5.72 (excluding) |
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | 9.0.40 (including) | 9.0.54 (excluding) |
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | 10.0.1 (including) | 10.0.12 (excluding) |
cpe:2.3:a:apache:tomcat:10.0.0:milestone10:*:*:*:*:*:* | ||
cpe:2.3:a:apache:tomcat:10.1.0:milestone1:*:*:*:*:*:* | ||
cpe:2.3:a:apache:tomcat:10.1.0:milestone2:*:*:*:*:*:* | ||
cpe:2.3:a:apache:tomcat:10.1.0:milestone3:*:*:*:*:*:* | ||
cpe:2.3:a:apache:tomcat:10.1.0:milestone4:*:*:*:*:*:* | ||
cpe:2.3:a:apache:tomcat:10.1.0:milestone5:*:*:*:*:*:* | ||
cpe:2.3:a:netapp:hci:-:*:*:*:*:*:*:* | ||
cpe:2.3:a:netapp:management_services_for_element_software:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:big_data_spatial_and_graph:*:*:*:*:*:*:*:* | 23.1 (excluding) | |
cpe:2.3:a:oracle:communications_diameter_signaling_router:*:*:*:*:*:*:*:* | 8.0.0.0 (including) | 8.5.0.2 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://kc.mcafee.com/corporate/index?page=content&id=SB10379
- https://lists.apache.org/thread.html/r8097a2d1550aa78e585fc77e602b9046e6d4099d8d132497c5387784%40%3Ccommits.myfaces.apache.org%3E
- https://lists.apache.org/thread.html/r83a35be60f06aca2065f188ee542b9099695d57ced2e70e0885f905c%40%3Cannounce.tomcat.apache.org%3E
- https://security.gentoo.org/glsa/202208-34
- https://security.netapp.com/advisory/ntap-20211104-0001/
- https://www.debian.org/security/2021/dsa-5009
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html