CVE-2021-30129: DoS/OOM leak vulnerability in Apache Mina SSHD Server
A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error. This issue affects the SFTP and port forwarding features of Apache Mina SSHD version 2.0.0 and later versions. It was addressed in Apache Mina SSHD 2.7.0
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/eap7-apache-sshdto a version that resolves this vulnerability.Fixed in 0:2.7.0-1.redhat_00001.1.el8ea - Upgrade
Upgrade
redhat/eap7-apache-sshdto a version that resolves this vulnerability.Fixed in 0:2.7.0-1.redhat_00001.1.el7ea - Upgrade
Upgrade
redhat/mina-sshdto a version that resolves this vulnerability.Fixed in 2.7.0 - Upgrade
Upgrade
Apache Mina SSHDto a version that resolves this vulnerability.Fixed in 2.7.0 - Compensating control
Limit exposure/usage of Apache Mina SSHD’s SFTP and port forwarding features until the server is upgraded to Apache Mina SSHD 2.7.0, since the issue affects these features in Mina SSHD 2.0.0 and later.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2021-30129?
The severity of CVE-2021-30129 is medium.
Which versions of Apache Mina SSHD are affected by CVE-2021-30129?
Apache Mina SSHD version 2.0.0 and later versions are affected by CVE-2021-30129.
How can an attacker exploit CVE-2021-30129?
An attacker can exploit CVE-2021-30129 by overflowing the server, causing an OutOfMemory error.
Has CVE-2021-30129 been fixed?
Yes, CVE-2021-30129 has been fixed in Apache Mina SSHD 2.7.0.
Where can I find more information about CVE-2021-30129?
You can find more information about CVE-2021-30129 in the references: [Reference 1](https://lists.apache.org/thread.html/r6d4f78e192a0c8eabd671a018da464024642980ecd24096bde6db36f%40%3Cusers.mina.apache.org%3E), [Reference 2](https://lists.apache.org/thread.html/r6d4f78e192a0c8eabd671a018da464024642980ecd24096bde6db36f@%3Cusers.mina.apache.org%3E), [Reference 3](https://github.com/apache/mina-sshd/pull/181/commits/5b5bd1dcfa0c2fc250e079e1eb).