CVE-2021-30129
published 2021-07-12CVE-2021-30129: A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error. This issue affects the SFTP and port…
PriorityP336medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
3.39%
87.6th percentile
A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error. This issue affects the SFTP and port forwarding features of Apache Mina SSHD version 2.0.0 and later versions. It was addressed in Apache Mina SSHD 2.7.0
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | sshd | >= 2.0.0 < 2.7.0 | 2.7.0 |
| apache_software_foundation | apache_mina_sshd | >= 2.0.0 < Apache Mina SSHD* | Apache Mina SSHD* |
| debian | libmina-sshd-java | — | — |
| oracle | banking_payments | — | — |
| oracle | banking_trade_finance | — | — |
| oracle | banking_treasury_management | — | — |
| oracle | communications_cloud_native_core_console | — | — |
| oracle | flexcube_universal_banking | — | — |
| oracle | flexcube_universal_banking | 14.0.0 – 14.3.0 | — |
| oracle | middleware_common_libraries_and_tools | — | — |
| oracle | middleware_common_libraries_and_tools | — | — |
| oracle | middleware_common_libraries_and_tools | — | — |
| oracle | oss_support_tools | — | — |
| oracle | retail_customer_management_and_segmentation_foundation | — | — |
| oracle | retail_customer_management_and_segmentation_foundation | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
vendor_debian6.5LOW
vendor_oracle6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle JD Edwards Risk Matrix: Interoperability SEC (Apache Mina SSHD) — CVE-2021-30129
vendor_oracle·2023-04-15·CVSS 6.5
CVE-2021-30129 [MEDIUM] Oracle Oracle JD Edwards Risk Matrix: Interoperability SEC (Apache Mina SSHD) — CVE-2021-30129
Oracle Oracle JD Edwards Risk Matrix: Interoperability SEC (Apache Mina SSHD) vulnerability
CVE: CVE-2021-30129
CVSS: 6.5
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: NextGen Installer issues (Apache MINA SSHD) — CVE-2021-30129
vendor_oracle·2022-07-15·CVSS 6.5
CVE-2021-30129 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: NextGen Installer issues (Apache MINA SSHD) — CVE-2021-30129
Oracle Oracle Fusion Middleware Risk Matrix: NextGen Installer issues (Apache MINA SSHD) vulnerability
CVE: CVE-2021-30129
CVSS: 6.5
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Oracle
Oracle Oracle Communications Risk Matrix: CNC Console (Apache MINA SSHD) — CVE-2021-30129
vendor_oracle·2022-04-15·CVSS 6.5
CVE-2021-30129 [MEDIUM] Oracle Oracle Communications Risk Matrix: CNC Console (Apache MINA SSHD) — CVE-2021-30129
Oracle Oracle Communications Risk Matrix: CNC Console (Apache MINA SSHD) vulnerability
CVE: CVE-2021-30129
CVSS: 6.5
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Red Hat
mina-sshd-core: Memory leak denial of service in Apache Mina SSHD Server
vendor_redhat·2021-07-12·CVSS 6.5
CVE-2021-30129 [MEDIUM] CWE-400 mina-sshd-core: Memory leak denial of service in Apache Mina SSHD Server
mina-sshd-core: Memory leak denial of service in Apache Mina SSHD Server
A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error. This issue affects the SFTP and port forwarding features of Apache Mina SSHD version 2.0.0 and later versions. It was addressed in Apache Mina SSHD 2.7.0
Statement: Red Hat OpenStack Platform's OpenDaylight will not be updated for this flaw because it was deprecated as of OpenStack Platform 14 and is only receiving security fixes for Critical flaws.
Package: sshd-core (Red Hat BPM Suite 6) - Out of support scope
Package: sshd-common (Red Hat build of Quarkus) - Not affected
Package: sshd-sftp (Red Hat Integration Camel K 1) - Affected
Package: sshd-sftp (Red Hat Integration Camel Quarkus 1) -
Debian
CVE-2021-30129: libmina-sshd-java - A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow ...
vendor_debian·2021·CVSS 6.5
CVE-2021-30129 [MEDIUM] CVE-2021-30129: libmina-sshd-java - A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow ...
A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error. This issue affects the SFTP and port forwarding features of Apache Mina SSHD version 2.0.0 and later versions. It was addressed in Apache Mina SSHD 2.7.0
Scope: local
forky: resolved
sid: resolved
trixie: resolved
OSV
Buffer Overflow in Apache Mina SSHD
osv·2021-08-02
CVE-2021-30129 [HIGH] Buffer Overflow in Apache Mina SSHD
Buffer Overflow in Apache Mina SSHD
A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error. This issue affects the SFTP and port forwarding features of Apache Mina SSHD version 2.0.0 and later versions. It was addressed in Apache Mina SSHD 2.7.0
GHSA
Buffer Overflow in Apache Mina SSHD
ghsa·2021-08-02
CVE-2021-30129 [HIGH] CWE-772 Buffer Overflow in Apache Mina SSHD
Buffer Overflow in Apache Mina SSHD
A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error. This issue affects the SFTP and port forwarding features of Apache Mina SSHD version 2.0.0 and later versions. It was addressed in Apache Mina SSHD 2.7.0
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2021-30129 mina-sshd-core: Memory leak denial of service in Apache Mina SSHD Server
bugzilla·2021-07-12·CVSS 6.5
CVE-2021-30129 [MEDIUM] CVE-2021-30129 mina-sshd-core: Memory leak denial of service in Apache Mina SSHD Server
CVE-2021-30129 mina-sshd-core: Memory leak denial of service in Apache Mina SSHD Server
A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error. This issue affects the SFTP and port forwarding features of Apache Mina SSHD version 2.0.0 and later versions. It was addressed in Apache Mina SSHD 2.7.0
References:
https://lists.apache.org/thread.html/r6d4f78e192a0c8eabd671a018da464024642980ecd24096bde6db36f%40%3Cusers.mina.apache.org%3E
https://lists.apache.org/thread.html/r6d4f78e192a0c8eabd671a018da464024642980ecd24096bde6db36f@%3Cusers.mina.apache.org%3E
Discussion:
Upstream Fix:
https://github.com/apache/mina-sshd/pull/181/commits/5b5bd1dcfa0c2fc250e079e1ebcd643b51f735eb
https://github.com/apache/mina-sshd/pull/181/commits
Tenable
Oracle April 2022 Critical Patch Update Addresses 221 CVEs
blogs_tenable·2022-04-20
Oracle April 2022 Critical Patch Update Addresses 221 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
http://www.openwall.com/lists/oss-security/2021/07/12/1https://lists.apache.org/thread.html/r6d4f78e192a0c8eabd671a018da464024642980ecd24096bde6db36f%40%3Cusers.mina.apache.org%3Ehttps://lists.apache.org/thread.html/r6d4f78e192a0c8eabd671a018da464024642980ecd24096bde6db36f%40%3Cusers.mina.apache.org%3Ehttps://lists.apache.org/thread.html/red01829efa2a8c893c4baff4f23c9312bd938543a9b8658e172b853b%40%3Cannounce.apache.org%3Ehttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttp://www.openwall.com/lists/oss-security/2021/07/12/1https://lists.apache.org/thread.html/r6d4f78e192a0c8eabd671a018da464024642980ecd24096bde6db36f%40%3Cusers.mina.apache.org%3Ehttps://lists.apache.org/thread.html/r6d4f78e192a0c8eabd671a018da464024642980ecd24096bde6db36f%40%3Cusers.mina.apache.org%3Ehttps://lists.apache.org/thread.html/red01829efa2a8c893c4baff4f23c9312bd938543a9b8658e172b853b%40%3Cannounce.apache.org%3Ehttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.html
2021-07-12
Published