First published: Mon Jul 12 2021(Updated: )
A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error. This issue affects the SFTP and port forwarding features of Apache Mina SSHD version 2.0.0 and later versions. It was addressed in Apache Mina SSHD 2.7.0
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/eap7-apache-sshd | <0:2.7.0-1.redhat_00001.1.el8ea | 0:2.7.0-1.redhat_00001.1.el8ea |
redhat/eap7-apache-sshd | <0:2.7.0-1.redhat_00001.1.el7ea | 0:2.7.0-1.redhat_00001.1.el7ea |
redhat/mina-sshd | <2.7.0 | 2.7.0 |
Apache Sshd | >=2.0.0<2.7.0 | |
Oracle Banking Payments | =14.5 | |
Oracle Banking Trade Finance | =14.5 | |
Oracle Banking Treasury Management | =14.5 | |
Oracle Communications Cloud Native Core Console | =1.9.0 | |
Oracle FLEXCUBE Universal Banking | >=14.0.0<=14.3.0 | |
Oracle FLEXCUBE Universal Banking | =14.5 | |
Oracle Middleware Common Libraries And Tools | =12.2.1.3.0 | |
Oracle Middleware Common Libraries And Tools | =12.2.1.4.0 | |
Oracle Middleware Common Libraries And Tools | =14.1.1.0.0 | |
Oracle OSS Support Tools | =2.12.42 | |
Oracle Retail Customer Management and Segmentation Foundation | =18.0 | |
Oracle Retail Customer Management and Segmentation Foundation | =19.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
The severity of CVE-2021-30129 is medium.
Apache Mina SSHD version 2.0.0 and later versions are affected by CVE-2021-30129.
An attacker can exploit CVE-2021-30129 by overflowing the server, causing an OutOfMemory error.
Yes, CVE-2021-30129 has been fixed in Apache Mina SSHD 2.7.0.
You can find more information about CVE-2021-30129 in the references: [Reference 1](https://lists.apache.org/thread.html/r6d4f78e192a0c8eabd671a018da464024642980ecd24096bde6db36f%40%3Cusers.mina.apache.org%3E), [Reference 2](https://lists.apache.org/thread.html/r6d4f78e192a0c8eabd671a018da464024642980ecd24096bde6db36f@%3Cusers.mina.apache.org%3E), [Reference 3](https://github.com/apache/mina-sshd/pull/181/commits/5b5bd1dcfa0c2fc250e079e1eb).