Uploaded image for project: 'TomEE'
  1. TomEE
  2. TOMEE-3812

TomEE plus is affected by CVE-2021-42340 vulnerability

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • 8.0.6, 8.0.7, 9.0.0-M7, 8.0.8
    • 8.0.9
    • TomEE Core Server

    Description

      Vulnerability description: 

      The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a memory leak that, over time, could lead to a denial of service via an OutOfMemoryError.

       

      Please confirm whether these memory leaks will impact TomEE ? 

      Attachments

        Activity

          People

            Unassigned Unassigned
            Jayaprakash Jayaprakash
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: