CVE-2020-27822 – org.wildfly:wildfly-parent
Package
Manager: maven
Name: org.wildfly:wildfly-parent
Vulnerable Version: >=19.0.0.final <21.0.2.final || =22.0.0.alpha1 || >=22.0.0.alpha1 <22.0.0.beta1
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS: 0.00339 pctl0.55989
Details
Wildfly has a memory leak vulnerability A flaw was found in Wildfly affecting versions 19.0.0.Final, 19.1.0.Final, 20.0.0.Final, 20.0.1.Final, and 21.0.0.Final. When an application uses the OpenTracing API's java-interceptors, there is a possibility of a memory leak. This flaw allows an attacker to impact the availability of the server. The highest threat from this vulnerability is to system availability.
Metadata
Created: 2022-05-24T17:35:40Z
Modified: 2023-08-23T13:48:00Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-qx3p-9mmp-4v8h/GHSA-qx3p-9mmp-4v8h.json
CWE IDs: ["CWE-401"]
Alternative ID: GHSA-qx3p-9mmp-4v8h
Finding: F067
Auto approve: 1