CVE-2021-41973: Apache MINA HTTP listener DOS
In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the beginning of the buffer and loops if there is more data than expected. Please update MINA to 2.1.5 or greater.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-41973?
CVE-2021-41973 is classified as a high-severity vulnerability due to its potential to cause denial of service through an infinite loop.
How do I fix CVE-2021-41973?
To fix CVE-2021-41973, update Apache MINA to version 2.1.5 or greater.
What software is affected by CVE-2021-41973?
CVE-2021-41973 affects Apache MINA versions prior to 2.1.5 and several Oracle products including Banking Payments and FLEXCUBE Universal Banking.
What impact does CVE-2021-41973 have on systems?
CVE-2021-41973 can lead to a denial of service by making the HTTP Header decoder loop indefinitely.
Is there a workaround for CVE-2021-41973?
There is no known workaround for CVE-2021-41973; upgrading to the patched version is recommended.