Wildfly-OpenSSL memory leak flaw
High severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Feb 22, 2024
Package
Affected versions
< 1.1.3.Final
Patched versions
1.1.3.Final
Description
Published by the National Vulnerability Database
Oct 6, 2020
Published to the GitHub Advisory Database
May 24, 2022
Reviewed
Jul 13, 2023
Last updated
Feb 22, 2024
A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM leading to a denial of service. The highest threat from this vulnerability is to system availability.
References