Memory leak in Undertow - CVE-2021-3690
Published: August 22, 2021
Vulnerability identifier: #VU56025
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-3690
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform DoS attack on the target system.
The vulnerability exists due memory leak when processing incoming PONG messages. A remote attacker can force the application to leak memory by sending an websocket PONG message and perform denial of service attack.
Affected software
Undertow
Oracle Communications Cloud Native Core Network Slice Selection Function
openEuler
undertow
undertow-javadoc
Fuse
Oracle Communications Cloud Native Core Network Slice Selection Function
openEuler
undertow
undertow-javadoc
Fuse
How to mitigate CVE-2021-3690
Install updates from vendor's website.
Undertow - update to 2.2.10
undertow - update to 1.4.0-7
undertow-javadoc - update to 1.4.0-7
Fuse - update to 7.10.0
undertow - update to 1.4.0-7
undertow-javadoc - update to 1.4.0-7
Fuse - update to 7.10.0