Korean
<< Back
VID 22986
Severity 40
Port 80, ...
Protocol TCP
Class WWW
Detailed Description The version of Tomcat installed on the remote host is prior to 8.5.72. It is, therefore, affected by a vulnerability as referenced in the fixed_in_apache_tomcat_8.5.72_security-8 advisory.

- The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a memory leak that, over time, could lead to a denial of service via an OutOfMemoryError. (CVE-2021-42340)

* References:
https://bz.apache.org/bugzilla/show_bug.cgi?id=63362
https://github.com/apache/tomcat/commit/d27535bdee95d252418201eb21e9d29476aa6b6a
https://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.5.72

* Platforms Affected:
Apache Tomcat Server versions 8.5.x prior to 8.5.72
Any operating system Any version
Recommendation Upgrade to the latest version of Apache Tomcat Server (8.5.72 or later), available from the Apache Software Foundation download site, http://tomcat.apache.org/
Related URL CVE-2021-42340 (CVE)
Related URL (SecurityFocus)
Related URL (ISS)