CVE-2020-25644
published 2020-10-06CVE-2020-25644: A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM…
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.18%
80.4th percentile
A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM leading to a denial of service. The highest threat from this vulnerability is to system availability.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | data_grid | — | — |
| redhat | jboss_data_grid | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_fuse | — | — |
| redhat | single_sign-on | — | — |
| redhat | wildfly_openssl | < 1.1.3 | 1.1.3 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Wildfly-OpenSSL memory leak flaw
ghsa·2022-05-24
CVE-2020-25644 [HIGH] CWE-401 Wildfly-OpenSSL memory leak flaw
Wildfly-OpenSSL memory leak flaw
A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM leading to a denial of service. The highest threat from this vulnerability is to system availability.
OSV
Wildfly-OpenSSL memory leak flaw
osv·2022-05-24
CVE-2020-25644 [HIGH] Wildfly-OpenSSL memory leak flaw
Wildfly-OpenSSL memory leak flaw
A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM leading to a denial of service. The highest threat from this vulnerability is to system availability.
Red Hat
wildfly-openssl: memory leak per HTTP session creation in WildFly OpenSSL
vendor_redhat·2020-09-22·CVSS 7.5
CVE-2020-25644 [HIGH] CWE-401 wildfly-openssl: memory leak per HTTP session creation in WildFly OpenSSL
wildfly-openssl: memory leak per HTTP session creation in WildFly OpenSSL
A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM leading to a denial of service. The highest threat from this vulnerability is to system availability.
A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. This flaw allows an attacker to cause an Out of memory (OOM) issue, leading to a denial of service. The highest threat from this vulnerability is to system availability.
Mitigation: There is currently no known mitigation for this issue.
Package: wildfly-openssl (Red Hat Decision Manager 7) - Not affected
Package: wildfly-openssl (Red Hat OpenShif
No detection rules found.
No public exploits indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1885485https://github.com/wildfly-security/wildfly-openssl-natives/pull/4/fileshttps://issues.redhat.com/browse/WFSSL-51https://security.netapp.com/advisory/ntap-20201016-0004/https://bugzilla.redhat.com/show_bug.cgi?id=1885485https://github.com/wildfly-security/wildfly-openssl-natives/pull/4/fileshttps://issues.redhat.com/browse/WFSSL-51https://security.netapp.com/advisory/ntap-20201016-0004/
2020-10-06
Published