CVE-2021-42340
published 2021-10-14CVE-2021-42340: The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
11.00%
95.4th percentile
The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a memory leak that, over time, could lead to a denial of service via an OutOfMemoryError.
Affected
36 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | >= 10.0.1 < 10.0.12 | 10.0.12 |
| apache | tomcat | >= 8.5.60 < 8.5.72 | 8.5.72 |
| apache | tomcat | >= 9.0.40 < 9.0.54 | 9.0.54 |
| apache_software_foundation | apache_tomcat | — | — |
| apache_software_foundation | apache_tomcat | — | — |
| apache_software_foundation | apache_tomcat | — | — |
| apache_software_foundation | apache_tomcat | — | — |
| debian | debian_linux | — | — |
| debian | tomcat9 | < tomcat9 9.0.54-1 (bookworm) | tomcat9 9.0.54-1 (bookworm) |
| oracle | agile_engineering_data_management | — | — |
| oracle | big_data_spatial_and_graph | < 23.1 | 23.1 |
| oracle | communications_diameter_signaling_router | 8.0.0.0 – 8.5.0.2 | — |
| oracle | hospitality_cruise_shipboard_property_management_system | — | — |
| oracle | managed_file_transfer | — | — |
| oracle | managed_file_transfer | — | — |
| oracle | middleware_common_libraries_and_tools | — | — |
| oracle | payment_interface | — | — |
| oracle | payment_interface | — | — |
| oracle | retail_customer_insights | — | — |
| oracle | retail_customer_insights | — | — |
| oracle | retail_data_extractor_for_merchandising | — | — |
| oracle | retail_data_extractor_for_merchandising | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_apache7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Big Data Graph Risk Matrix: Big Data Graph (Apache Tomcat) — CVE-2021-42340
vendor_oracle·2022-07-15·CVSS 7.5
CVE-2021-42340 [HIGH] Oracle Oracle Big Data Graph Risk Matrix: Big Data Graph (Apache Tomcat) — CVE-2021-42340
Oracle Oracle Big Data Graph Risk Matrix: Big Data Graph (Apache Tomcat) vulnerability
CVE: CVE-2021-42340
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Oracle
Oracle Oracle Commerce Risk Matrix: Content Acquisition System (Apache Tomcat) — CVE-2021-42340
vendor_oracle·2022-04-15·CVSS 7.5
CVE-2021-42340 [HIGH] Oracle Oracle Commerce Risk Matrix: Content Acquisition System (Apache Tomcat) — CVE-2021-42340
Oracle Oracle Commerce Risk Matrix: Content Acquisition System (Apache Tomcat) vulnerability
CVE: CVE-2021-42340
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Oracle
Oracle Oracle Communications Risk Matrix: Platform (Apache Tomcat) — CVE-2021-42340
vendor_oracle·2022-01-15·CVSS 7.5
CVE-2021-42340 [HIGH] Oracle Oracle Communications Risk Matrix: Platform (Apache Tomcat) — CVE-2021-42340
Oracle Oracle Communications Risk Matrix: Platform (Apache Tomcat) vulnerability
CVE: CVE-2021-42340
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Red Hat
tomcat: OutOfMemoryError caused by HTTP upgrade connection leak could lead to DoS
vendor_redhat·2021-10-14·CVSS 7.5
CVE-2021-42340 [HIGH] CWE-772 tomcat: OutOfMemoryError caused by HTTP upgrade connection leak could lead to DoS
tomcat: OutOfMemoryError caused by HTTP upgrade connection leak could lead to DoS
The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a memory leak that, over time, could lead to a denial of service via an OutOfMemoryError.
A memory leak flaw was found in Apache Tomcat, where an HTTP upgrade connection does not release for WebSocket connections once the WebSocket connection is closed. If a sufficient number of such requests are made, an OutOfMemoryError occurs, leading to a denial of service. The highest threat from this vulnerab
Debian
CVE-2021-42340: tomcat9 - The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1...
vendor_debian·2021·CVSS 7.5
CVE-2021-42340 [HIGH] CVE-2021-42340: tomcat9 - The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1...
The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a memory leak that, over time, could lead to a denial of service via an OutOfMemoryError.
Scope: local
bookworm: resolved (fixed in 9.0.54-1)
bullseye: resolved (fixed in 9.0.43-2~deb11u3)
forky: resolved (fixed in 9.0.54-1)
sid: resolved (fixed in 9.0.54-1)
trixie: resolved (fixed in 9.0.54-1)
Apache
Apache tomcat: CVE-2021-42340
vendor_apache·CVSS 7.5
CVE-2021-42340 [HIGH] Apache tomcat: CVE-2021-42340
Apache tomcat: CVE-2021-42340
The fix for bug 63362 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the WebSocket connection was closed. This created a memory leak that, over time, could lead to a denial of service via an OutOfMemoryError. This was fixed with commit d27535bd . The memory leak was reported publicly via the users mailing list on 23 September 2021. The security implications were identified by the Tomcat Security team the same day. The issue was made public on 14 October 2021. Affects: 8.5.60 to 8.5.71 15 June 2021 Fixed in Apache Tomcat 8.5.68 Note: The issue below was fixed in Apache Tomcat 8.5.67 but the release vote for the 8.5.67 release candidate did not pass. Therefore, altho
OSV
Missing Release of Resource after Effective Lifetime in Apache Tomcat
osv·2021-10-15
CVE-2021-42340 [HIGH] Missing Release of Resource after Effective Lifetime in Apache Tomcat
Missing Release of Resource after Effective Lifetime in Apache Tomcat
The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a memory leak that, over time, could lead to a denial of service via an OutOfMemoryError.
GHSA
Missing Release of Resource after Effective Lifetime in Apache Tomcat
ghsa·2021-10-15
CVE-2021-42340 [HIGH] CWE-772 Missing Release of Resource after Effective Lifetime in Apache Tomcat
Missing Release of Resource after Effective Lifetime in Apache Tomcat
The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a memory leak that, over time, could lead to a denial of service via an OutOfMemoryError.
OSV
CVE-2021-42340: The fix for bug 63362 present in Apache Tomcat 10
osv·2021-10-14·CVSS 7.5
CVE-2021-42340 [HIGH] CVE-2021-42340: The fix for bug 63362 present in Apache Tomcat 10
The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a memory leak that, over time, could lead to a denial of service via an OutOfMemoryError.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2021-42340 tomcat: OutOfMemoryError caused by HTTP upgrade connection leak could lead to DoS
bugzilla·2021-10-15·CVSS 7.5
CVE-2021-42340 [HIGH] CVE-2021-42340 tomcat: OutOfMemoryError caused by HTTP upgrade connection leak could lead to DoS
CVE-2021-42340 tomcat: OutOfMemoryError caused by HTTP upgrade connection leak could lead to DoS
Apache Tomcat did not properly release an HTTP upgrade connection for WebSocket connections once the WebSocket connection was closed. This created a memory leak that, over time, could lead to a denial of service via an OutOfMemoryError. This issue affects the version of Apache Tomcat 10.1.0-M1 to 10.1.0-M5; Apache Tomcat 10.0.0-M10 to 10.0.11; Apache Tomcat 9.0.40 to 9.0.53; Apache Tomcat 8.5.60 to 8.5.71.
Upstream commits:
Tomcat 10.1: https://github.com/apache/tomcat/commit/d5a6660cba7f51589468937bf3bbad4db7810371
Tomcat 10.0: https://github.com/apache/tomcat/commit/31d62426645824bdfe076a0c0eafa904d90b4fb9
Tomcat 9.0: https://github.com/apache/tomcat/commit/80f1438ec45e77a07b96419808971838d
Tenable
Oracle April 2022 Critical Patch Update Addresses 221 CVEs
blogs_tenable·2022-04-20
Oracle April 2022 Critical Patch Update Addresses 221 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
https://kc.mcafee.com/corporate/index?page=content&id=SB10379https://lists.apache.org/thread.html/r8097a2d1550aa78e585fc77e602b9046e6d4099d8d132497c5387784%40%3Ccommits.myfaces.apache.org%3Ehttps://lists.apache.org/thread.html/r83a35be60f06aca2065f188ee542b9099695d57ced2e70e0885f905c%40%3Cannounce.tomcat.apache.org%3Ehttps://security.gentoo.org/glsa/202208-34https://security.netapp.com/advisory/ntap-20211104-0001/https://www.debian.org/security/2021/dsa-5009https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://kc.mcafee.com/corporate/index?page=content&id=SB10379https://lists.apache.org/thread.html/r8097a2d1550aa78e585fc77e602b9046e6d4099d8d132497c5387784%40%3Ccommits.myfaces.apache.org%3Ehttps://lists.apache.org/thread.html/r83a35be60f06aca2065f188ee542b9099695d57ced2e70e0885f905c%40%3Cannounce.tomcat.apache.org%3Ehttps://security.gentoo.org/glsa/202208-34https://security.netapp.com/advisory/ntap-20211104-0001/https://www.debian.org/security/2021/dsa-5009https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.html
2021-10-14
Published