The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a memory leak that, over time, could lead to a denial of service via an OutOfMemoryError.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2021-10-14T19:55:14

Updated: 2024-08-04T03:30:38.354Z

Reserved: 2021-10-13T00:00:00

Link: CVE-2021-42340

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-10-14T20:15:09.060

Modified: 2023-11-07T03:39:09.487

Link: CVE-2021-42340

cve-icon Redhat

Severity : Important

Publid Date: 2021-10-14T00:00:00Z

Links: CVE-2021-42340 - Bugzilla