Description
The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a memory leak that, over time, could lead to a denial of service via an OutOfMemoryError.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-5009-1 | tomcat9 security update |
EUVD |
EUVD-2021-2266 | The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a memory leak that, over time, could lead to a denial of service via an OutOfMemoryError. |
Github GHSA |
GHSA-wph7-x527-w3h5 | Missing Release of Resource after Effective Lifetime in Apache Tomcat |
References
History
No history.
Subscriptions
Apache
Subscribe
Tomcat
Subscribe
Debian
Subscribe
Debian Linux
Subscribe
Netapp
Subscribe
Hci
Subscribe
Management Services For Element Software
Subscribe
Oracle
Subscribe
Agile Engineering Data Management
Subscribe
Big Data Spatial And Graph
Subscribe
Communications Diameter Signaling Router
Subscribe
Hospitality Cruise Shipboard Property Management System
Subscribe
Managed File Transfer
Subscribe
Middleware Common Libraries And Tools
Subscribe
Payment Interface
Subscribe
Retail Customer Insights
Subscribe
Retail Data Extractor For Merchandising
Subscribe
Retail Eftlink
Subscribe
Retail Financial Integration
Subscribe
Retail Store Inventory Management
Subscribe
Sd-wan Edge
Subscribe
Taleo Platform
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Jboss Enterprise Web Server
Subscribe
Jboss Fuse
Subscribe
Openshift Application Runtimes
Subscribe
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-04T03:30:38.354Z
Reserved: 2021-10-13T00:00:00.000Z
Link: CVE-2021-42340
No data.
Status : Modified
Published: 2021-10-14T20:15:09.060
Modified: 2024-11-21T06:27:38.363
Link: CVE-2021-42340
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD
Github GHSA