[MAVEN:GHSA-97HP-6Q9G-5CW2] Uncontrolled Resource Consumption in WildFly

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in a loop, generating new connections which are not properly closed while not able to connect to domain-controller. This flaw allows an attacker to cause an Out of memory (OOM) issue, leading to a denial of service. The highest threat from this vulnerability is to system availability.

Package Affected Version
pkg:maven/org.wildfly/wildfly-dist <= 21.0.0
Package Fixed Version
pkg:maven/org.wildfly/wildfly-dist = 21.0.1
ID
MAVEN:GHSA-97HP-6Q9G-5CW2
Severity
moderate
URL
https://github.com/advisories/GHSA-97hp-6q9g-5cw2
Published
2022-05-24T17:32:58
(2 years ago)
Modified
2023-01-27T05:02:59
(20 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.wildfly/wildfly-dist org.wildfly wildfly-dist <= 21.0.0
Fixed pkg:maven/org.wildfly/wildfly-dist org.wildfly wildfly-dist = 21.0.1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...