First published: Tue Sep 22 2020(Updated: )
A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM leading to a denial of service. The highest threat from this vulnerability is to system availability.
Credit: secalert@redhat.com secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.wildfly.openssl:wildfly-openssl-natives-parent | <1.1.3.Final | 1.1.3.Final |
redhat/eap7-activemq-artemis | <0:2.9.0-6.redhat_00016.1.el6ea | 0:2.9.0-6.redhat_00016.1.el6ea |
redhat/eap7-fge-btf | <0:1.2.0-1.redhat_00007.1.el6ea | 0:1.2.0-1.redhat_00007.1.el6ea |
redhat/eap7-fge-msg-simple | <0:1.1.0-1.redhat_00007.1.el6ea | 0:1.1.0-1.redhat_00007.1.el6ea |
redhat/eap7-hal-console | <0:3.2.11-1.Final_redhat_00001.1.el6ea | 0:3.2.11-1.Final_redhat_00001.1.el6ea |
redhat/eap7-hibernate-validator | <0:6.0.21-1.Final_redhat_00001.1.el6ea | 0:6.0.21-1.Final_redhat_00001.1.el6ea |
redhat/eap7-jackson-annotations | <0:2.10.4-1.redhat_00002.1.el6ea | 0:2.10.4-1.redhat_00002.1.el6ea |
redhat/eap7-jackson-core | <0:2.10.4-1.redhat_00002.1.el6ea | 0:2.10.4-1.redhat_00002.1.el6ea |
redhat/eap7-jackson-coreutils | <0:1.6.0-1.redhat_00006.1.el6ea | 0:1.6.0-1.redhat_00006.1.el6ea |
redhat/eap7-jackson-jaxrs-providers | <0:2.10.4-1.redhat_00002.1.el6ea | 0:2.10.4-1.redhat_00002.1.el6ea |
redhat/eap7-jackson-modules-base | <0:2.10.4-3.redhat_00002.1.el6ea | 0:2.10.4-3.redhat_00002.1.el6ea |
redhat/eap7-jackson-modules-java8 | <0:2.10.4-1.redhat_00002.1.el6ea | 0:2.10.4-1.redhat_00002.1.el6ea |
redhat/eap7-jasypt | <0:1.9.3-1.redhat_00002.1.el6ea | 0:1.9.3-1.redhat_00002.1.el6ea |
redhat/eap7-jboss-marshalling | <0:2.0.10-1.Final_redhat_00001.1.el6ea | 0:2.0.10-1.Final_redhat_00001.1.el6ea |
redhat/eap7-jboss-remoting | <0:5.0.19-1.Final_redhat_00001.1.el6ea | 0:5.0.19-1.Final_redhat_00001.1.el6ea |
redhat/eap7-jboss-server-migration | <0:1.7.2-3.Final_redhat_00004.1.el6ea | 0:1.7.2-3.Final_redhat_00004.1.el6ea |
redhat/eap7-jboss-xnio-base | <0:3.7.11-1.Final_redhat_00001.1.el6ea | 0:3.7.11-1.Final_redhat_00001.1.el6ea |
redhat/eap7-undertow | <0:2.0.32-1.SP1_redhat_00001.1.el6ea | 0:2.0.32-1.SP1_redhat_00001.1.el6ea |
redhat/eap7-wildfly | <0:7.3.4-3.GA_redhat_00003.1.el6ea | 0:7.3.4-3.GA_redhat_00003.1.el6ea |
redhat/eap7-wildfly-elytron | <0:1.10.9-1.Final_redhat_00001.1.el6ea | 0:1.10.9-1.Final_redhat_00001.1.el6ea |
redhat/eap7-wildfly-openssl | <0:1.0.12-1.Final_redhat_00001.1.el6ea | 0:1.0.12-1.Final_redhat_00001.1.el6ea |
redhat/eap7-activemq-artemis | <0:2.9.0-6.redhat_00016.1.el7ea | 0:2.9.0-6.redhat_00016.1.el7ea |
redhat/eap7-fge-btf | <0:1.2.0-1.redhat_00007.1.el7ea | 0:1.2.0-1.redhat_00007.1.el7ea |
redhat/eap7-fge-msg-simple | <0:1.1.0-1.redhat_00007.1.el7ea | 0:1.1.0-1.redhat_00007.1.el7ea |
redhat/eap7-hal-console | <0:3.2.11-1.Final_redhat_00001.1.el7ea | 0:3.2.11-1.Final_redhat_00001.1.el7ea |
redhat/eap7-hibernate-validator | <0:6.0.21-1.Final_redhat_00001.1.el7ea | 0:6.0.21-1.Final_redhat_00001.1.el7ea |
redhat/eap7-jackson-annotations | <0:2.10.4-1.redhat_00002.1.el7ea | 0:2.10.4-1.redhat_00002.1.el7ea |
redhat/eap7-jackson-core | <0:2.10.4-1.redhat_00002.1.el7ea | 0:2.10.4-1.redhat_00002.1.el7ea |
redhat/eap7-jackson-coreutils | <0:1.6.0-1.redhat_00006.1.el7ea | 0:1.6.0-1.redhat_00006.1.el7ea |
redhat/eap7-jackson-jaxrs-providers | <0:2.10.4-1.redhat_00002.1.el7ea | 0:2.10.4-1.redhat_00002.1.el7ea |
redhat/eap7-jackson-modules-base | <0:2.10.4-3.redhat_00002.1.el7ea | 0:2.10.4-3.redhat_00002.1.el7ea |
redhat/eap7-jackson-modules-java8 | <0:2.10.4-1.redhat_00002.1.el7ea | 0:2.10.4-1.redhat_00002.1.el7ea |
redhat/eap7-jasypt | <0:1.9.3-1.redhat_00002.1.el7ea | 0:1.9.3-1.redhat_00002.1.el7ea |
redhat/eap7-jboss-marshalling | <0:2.0.10-1.Final_redhat_00001.1.el7ea | 0:2.0.10-1.Final_redhat_00001.1.el7ea |
redhat/eap7-jboss-remoting | <0:5.0.19-1.Final_redhat_00001.1.el7ea | 0:5.0.19-1.Final_redhat_00001.1.el7ea |
redhat/eap7-jboss-server-migration | <0:1.7.2-3.Final_redhat_00004.1.el7ea | 0:1.7.2-3.Final_redhat_00004.1.el7ea |
redhat/eap7-jboss-xnio-base | <0:3.7.11-1.Final_redhat_00001.1.el7ea | 0:3.7.11-1.Final_redhat_00001.1.el7ea |
redhat/eap7-undertow | <0:2.0.32-1.SP1_redhat_00001.1.el7ea | 0:2.0.32-1.SP1_redhat_00001.1.el7ea |
redhat/eap7-wildfly | <0:7.3.4-3.GA_redhat_00003.1.el7ea | 0:7.3.4-3.GA_redhat_00003.1.el7ea |
redhat/eap7-wildfly-elytron | <0:1.10.9-1.Final_redhat_00001.1.el7ea | 0:1.10.9-1.Final_redhat_00001.1.el7ea |
redhat/eap7-wildfly-openssl | <0:1.0.12-1.Final_redhat_00001.1.el7ea | 0:1.0.12-1.Final_redhat_00001.1.el7ea |
redhat/eap7-activemq-artemis | <0:2.9.0-6.redhat_00016.1.el8ea | 0:2.9.0-6.redhat_00016.1.el8ea |
redhat/eap7-fge-btf | <0:1.2.0-1.redhat_00007.1.el8ea | 0:1.2.0-1.redhat_00007.1.el8ea |
redhat/eap7-fge-msg-simple | <0:1.1.0-1.redhat_00007.1.el8ea | 0:1.1.0-1.redhat_00007.1.el8ea |
redhat/eap7-hal-console | <0:3.2.11-1.Final_redhat_00001.1.el8ea | 0:3.2.11-1.Final_redhat_00001.1.el8ea |
redhat/eap7-hibernate-validator | <0:6.0.21-1.Final_redhat_00001.1.el8ea | 0:6.0.21-1.Final_redhat_00001.1.el8ea |
redhat/eap7-jackson-annotations | <0:2.10.4-1.redhat_00002.1.el8ea | 0:2.10.4-1.redhat_00002.1.el8ea |
redhat/eap7-jackson-core | <0:2.10.4-1.redhat_00002.1.el8ea | 0:2.10.4-1.redhat_00002.1.el8ea |
redhat/eap7-jackson-coreutils | <0:1.6.0-1.redhat_00006.1.el8ea | 0:1.6.0-1.redhat_00006.1.el8ea |
redhat/eap7-jackson-jaxrs-providers | <0:2.10.4-1.redhat_00002.1.el8ea | 0:2.10.4-1.redhat_00002.1.el8ea |
redhat/eap7-jackson-modules-base | <0:2.10.4-3.redhat_00002.1.el8ea | 0:2.10.4-3.redhat_00002.1.el8ea |
redhat/eap7-jackson-modules-java8 | <0:2.10.4-1.redhat_00002.1.el8ea | 0:2.10.4-1.redhat_00002.1.el8ea |
redhat/eap7-jasypt | <0:1.9.3-1.redhat_00002.1.el8ea | 0:1.9.3-1.redhat_00002.1.el8ea |
redhat/eap7-jboss-marshalling | <0:2.0.10-1.Final_redhat_00001.1.el8ea | 0:2.0.10-1.Final_redhat_00001.1.el8ea |
redhat/eap7-jboss-remoting | <0:5.0.19-1.Final_redhat_00001.1.el8ea | 0:5.0.19-1.Final_redhat_00001.1.el8ea |
redhat/eap7-jboss-server-migration | <0:1.7.2-3.Final_redhat_00004.1.el8ea | 0:1.7.2-3.Final_redhat_00004.1.el8ea |
redhat/eap7-jboss-xnio-base | <0:3.7.11-1.Final_redhat_00001.1.el8ea | 0:3.7.11-1.Final_redhat_00001.1.el8ea |
redhat/eap7-undertow | <0:2.0.32-1.SP1_redhat_00001.1.el8ea | 0:2.0.32-1.SP1_redhat_00001.1.el8ea |
redhat/eap7-wildfly | <0:7.3.4-3.GA_redhat_00003.1.el8ea | 0:7.3.4-3.GA_redhat_00003.1.el8ea |
redhat/eap7-wildfly-elytron | <0:1.10.9-1.Final_redhat_00001.1.el8ea | 0:1.10.9-1.Final_redhat_00001.1.el8ea |
redhat/eap7-wildfly-openssl | <0:1.0.12-1.Final_redhat_00001.1.el8ea | 0:1.0.12-1.Final_redhat_00001.1.el8ea |
Redhat Wildfly Openssl | <1.1.3 | |
Redhat Data Grid | =8.0 | |
Redhat Jboss Data Grid | =7.0 | |
Redhat Jboss Enterprise Application Platform | =7.0.0 | |
Redhat Jboss Fuse | =7.0.0 | |
Redhat Openshift Application Runtimes | ||
Redhat Single Sign-on | =7.0 | |
NetApp OnCommand Insight | ||
NetApp OnCommand Workflow Automation | ||
NetApp Service Level Manager | ||
redhat/wildfly-openssl | <1.1.3. | 1.1.3. |
Redhat Jboss Data Grid | =7.0.0 |
There is currently no known mitigation for this issue.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)