CVE-2021-42340
—CVSS 3.1
7.5 high
EPSS
12%p96
Published
()
Modified
Description
The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a memory leak that, over time, could lead to a denial of service via an OutOfMemoryError.
- Vendors
- apachenetappdebianoracle
- Products
- tomcat, hci, management services for element software, debian linux, agile engineering data management, big data spatial and graph, communications diameter signaling router, hospitality cruise shipboard property management system, managed file transfer, middleware common libraries and tools, payment interface, retail customer insights
- Weakness
- CWE-772
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.