CVE-2021-41973
published 2021-11-01CVE-2021-41973: In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header…
PriorityP432medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
4.33%
90.1th percentile
In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the beginning of the buffer and loops if there is more data than expected. Please update MINA to 2.1.5 or greater.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | mina | < 2.0.22 | 2.0.22 |
| apache | mina | >= 2.1.0 < 2.1.5 | 2.1.5 |
| apache_software_foundation | apache_mina | >= Apache MINA < 2.1.5 | 2.1.5 |
| debian | mina | < mina2 2.1.5-1 (bookworm) | mina2 2.1.5-1 (bookworm) |
| debian | mina2 | < mina2 2.1.5-1 (bookworm) | mina2 2.1.5-1 (bookworm) |
| oracle | banking_payments | — | — |
| oracle | banking_trade_finance_process_management | — | — |
| oracle | banking_treasury_management | — | — |
| oracle | communications_cloud_native_core_console | — | — |
| oracle | customer_management_and_segmentation_foundation | — | — |
| oracle | customer_management_and_segmentation_foundation | — | — |
| oracle | flexcube_universal_banking | — | — |
| oracle | flexcube_universal_banking | 14.0 – 14.3 | — |
| oracle | fusion_middleware_common_libraries_and_tools | — | — |
| oracle | fusion_middleware_common_libraries_and_tools | — | — |
| oracle | fusion_middleware_common_libraries_and_tools | — | — |
| oracle | oss_support_tools | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5LOW
vendor_oracle6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle JD Edwards Risk Matrix: Interoperability SEC (Apache Mina) — CVE-2021-41973
vendor_oracle·2023-04-15·CVSS 6.5
CVE-2021-41973 [MEDIUM] Oracle Oracle JD Edwards Risk Matrix: Interoperability SEC (Apache Mina) — CVE-2021-41973
Oracle Oracle JD Edwards Risk Matrix: Interoperability SEC (Apache Mina) vulnerability
CVE: CVE-2021-41973
CVSS: 6.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Oracle
Oracle Oracle Support Tools Risk Matrix: Diagnostic Assistant (Apache MINA) — CVE-2021-41973
vendor_oracle·2022-04-15·CVSS 6.5
CVE-2021-41973 [MEDIUM] Oracle Oracle Support Tools Risk Matrix: Diagnostic Assistant (Apache MINA) — CVE-2021-41973
Oracle Oracle Support Tools Risk Matrix: Diagnostic Assistant (Apache MINA) vulnerability
CVE: CVE-2021-41973
CVSS: 6.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Red Hat
mina-core: infinite loop may lead to DoS
vendor_redhat·2021-11-01·CVSS 6.5
CVE-2021-41973 [MEDIUM] CWE-835 mina-core: infinite loop may lead to DoS
mina-core: infinite loop may lead to DoS
In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the beginning of the buffer and loops if there is more data than expected. Please update MINA to 2.1.5 or greater.
Package: mina-core (Red Hat BPM Suite 6) - Out of support scope
Package: mina-core (Red Hat Fuse 7) - Not affected
Package: mina-core (Red Hat Integration Camel K 1) - Not affected
Package: mina-core (Red Hat Integration Camel Quarkus 1) - Not affected
Package: mina-core (Red Hat JBoss A-MQ 6) - Out of support scope
Package: mina-core (Red Hat JBoss BRMS 5) - Out of support scope
Package: mina-core (Red Hat JBoss BRMS 6) - Out of support scope
Package: mina-cor
Debian
CVE-2021-41973: mina - In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTT...
vendor_debian·2021·CVSS 6.5
CVE-2021-41973 [MEDIUM] CVE-2021-41973: mina - In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTT...
In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the beginning of the buffer and loops if there is more data than expected. Please update MINA to 2.1.5 or greater.
Scope: local
bookworm: resolved
bullseye: resolved
OSV
Infinite loop in Apache MINA
osv·2021-11-03
CVE-2021-41973 [MEDIUM] Infinite loop in Apache MINA
Infinite loop in Apache MINA
In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the beginning of the buffer and loops if there is more data than expected. Please update MINA to 2.1.5 or greater.
GHSA
Infinite loop in Apache MINA
ghsa·2021-11-03
CVE-2021-41973 [MEDIUM] CWE-835 Infinite loop in Apache MINA
Infinite loop in Apache MINA
In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the beginning of the buffer and loops if there is more data than expected. Please update MINA to 2.1.5 or greater.
OSV
CVE-2021-41973: In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely
osv·2021-11-01·CVSS 6.5
CVE-2021-41973 [MEDIUM] CVE-2021-41973: In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely
In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the beginning of the buffer and loops if there is more data than expected. Please update MINA to 2.1.5 or greater.
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2021/11/01/2http://www.openwall.com/lists/oss-security/2021/11/01/8https://lists.apache.org/thread.html/r0b907da9340d5ff4e6c1a4798ef4e79700a668657f27cca8a39e9250%40%3Cdev.mina.apache.org%3Ehttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttp://www.openwall.com/lists/oss-security/2021/11/01/2http://www.openwall.com/lists/oss-security/2021/11/01/8https://lists.apache.org/thread.html/r0b907da9340d5ff4e6c1a4798ef4e79700a668657f27cca8a39e9250%40%3Cdev.mina.apache.org%3Ehttps://www.oracle.com/security-alerts/cpuapr2022.html
2021-11-01
Published