ZeroHour

CVE-2021-42340

CVSS 3.1
7.5 high
EPSS
12%p96
Published
()
Modified
Description

The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a memory leak that, over time, could lead to a denial of service via an OutOfMemoryError.

Vendors
apachenetappdebianoracle
Products
tomcat, hci, management services for element software, debian linux, agile engineering data management, big data spatial and graph, communications diameter signaling router, hospitality cruise shipboard property management system, managed file transfer, middleware common libraries and tools, payment interface, retail customer insights
Weakness
CWE-772
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.