GHSA-qx3p-9mmp-4v8h

Suggest an improvement
Source
https://github.com/advisories/GHSA-qx3p-9mmp-4v8h
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-qx3p-9mmp-4v8h/GHSA-qx3p-9mmp-4v8h.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-qx3p-9mmp-4v8h
Aliases
Published
2022-05-24T17:35:40Z
Modified
2023-12-06T00:45:28.398894Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Wildfly has a memory leak vulnerability
Details

A flaw was found in Wildfly affecting versions 19.0.0.Final, 19.1.0.Final, 20.0.0.Final, 20.0.1.Final, and 21.0.0.Final. When an application uses the OpenTracing API's java-interceptors, there is a possibility of a memory leak. This flaw allows an attacker to impact the availability of the server. The highest threat from this vulnerability is to system availability.

References

Affected packages

Maven / org.wildfly:wildfly-parent

Package

Name
org.wildfly:wildfly-parent
View open source insights on deps.dev
Purl
pkg:maven/org.wildfly/wildfly-parent

Affected ranges

Type
ECOSYSTEM
Events
Introduced
19.0.0.Final
Fixed
21.0.2.Final

Affected versions

19.*

19.0.0.Final
19.1.0.Final

20.*

20.0.0.Beta1
20.0.0.Final
20.0.1.Final

21.*

21.0.0.Beta1
21.0.0.Final
21.0.1.Final

Maven / org.wildfly:wildfly-parent

Package

Name
org.wildfly:wildfly-parent
View open source insights on deps.dev
Purl
pkg:maven/org.wildfly/wildfly-parent

Affected ranges

Type
ECOSYSTEM
Events
Introduced
22.0.0.Alpha1
Fixed
22.0.0.Beta1

Affected versions

22.*

22.0.0.Alpha1