Memory leak in Undertow - CVE-2021-3690

 

Memory leak in Undertow - CVE-2021-3690

Published: August 22, 2021


Vulnerability identifier: #VU56025
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-3690
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform DoS attack on the target system.

The vulnerability exists due memory leak when processing incoming PONG messages. A remote attacker can force the application to leak memory by sending an websocket PONG message and perform denial of service attack.


Affected software

Undertow
Oracle Communications Cloud Native Core Network Slice Selection Function
openEuler
undertow
undertow-javadoc
Fuse

How to mitigate CVE-2021-3690

Install updates from vendor's website.

Undertow - update to 2.2.10
undertow - update to 1.4.0-7
undertow-javadoc - update to 1.4.0-7
Fuse - update to 7.10.0

External References

Related Security Bulletins