CVE-2021-37137
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved skippable chunks until the whole chunk was received which may lead to excessive memory usage as well. This vulnerability can be triggered by supplying malicious input that decompresses to a very big size (via a network stream or a file) or by sending a huge skippable chunk.
Affected (27)
Products: Netty: Netty · Oracle: Banking Apis, Banking Digital Experience, Commerce Guided Search, Communications Brm Elastic Charging Engine, Communications Cloud Native Core Binding Support Function, Communications Diameter Signaling Router, Peoplesoft Enterprise Peopletools, Webcenter Portal · Quarkus: Quarkus · +2 more
Show all products
Netty: Netty · Oracle: Banking Apis, Banking Digital Experience, Commerce Guided Search, Communications Brm Elastic Charging Engine, Communications Cloud Native Core Binding Support Function, Communications Diameter Signaling Router, Peoplesoft Enterprise Peopletools, Webcenter Portal · Quarkus: Quarkus · Netapp: Oncommand Insight · Debian: Debian Linux
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 18.1 to 18.3 | |
| Version 18.1 | |
| Version 11.3.2 | |
| Before 12.0.0.4.6 | |
| Version 1.10.0 | |
| From 8.0.0.0 to 8.5.0.2 | |
| Version 8.57 | |
| Version 12.2.1.3.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0 |
References (26)
Source: reefs@jfrog.com
Third Party Advisory
Source: reefs@jfrog.com
Source: reefs@jfrog.com
Source: reefs@jfrog.com
Source: reefs@jfrog.com
Source: reefs@jfrog.com
Source: reefs@jfrog.com
Source: reefs@jfrog.com
Mailing ListThird Party Advisory
Source: reefs@jfrog.com
PatchThird Party Advisory
Source: reefs@jfrog.com
PatchThird Party Advisory
Source: reefs@jfrog.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.