CVE-2021-30129
Summary
| CVE | CVE-2021-30129 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-07-12 12:15:00 UTC |
| Updated | 2023-11-07 03:32:00 UTC |
| Description | A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error. This issue affects the SFTP and port forwarding features of Apache Mina SSHD version 2.0.0 and later versions. It was addressed in Apache Mina SSHD 2.7.0 |
Risk And Classification
Problem Types: CWE-772
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Mina | All | All | All | All |
| Application | Apache | Sshd | All | All | All | All |
| Application | Oracle | Banking Payments | 14.5 | All | All | All |
| Application | Oracle | Banking Trade Finance | 14.5 | All | All | All |
| Application | Oracle | Banking Treasury Management | 14.5 | All | All | All |
| Application | Oracle | Communications Cloud Native Core Console | 1.9.0 | All | All | All |
| Application | Oracle | Flexcube Universal Banking | 14.5 | All | All | All |
| Application | Oracle | Flexcube Universal Banking | All | All | All | All |
| Application | Oracle | Middleware Common Libraries And Tools | 12.2.1.3.0 | All | All | All |
| Application | Oracle | Middleware Common Libraries And Tools | 12.2.1.4.0 | All | All | All |
| Application | Oracle | Middleware Common Libraries And Tools | 14.1.1.0.0 | All | All | All |
| Application | Oracle | Oss Support Tools | 2.12.42 | All | All | All |
| Application | Oracle | Retail Customer Management And Segmentation Foundation | 18.0 | All | All | All |
| Application | Oracle | Retail Customer Management And Segmentation Foundation | 19.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [announce] 20210712 CVE-2021-30129: DoS/OOM leak vulnerability in Apache Mina SSHD Server | lists.apache.org | ||
| Pony Mail! | MLIST | lists.apache.org | |
| oss-security - CVE-2021-30129: DoS/OOM leak vulnerability in Apache Mina SSHD Server | MLIST | www.openwall.com | |
| Oracle Critical Patch Update Advisory - April 2022 | MISC | www.oracle.com | |
| Pony Mail! | MLIST | lists.apache.org | |
| Pony Mail! | CONFIRM | lists.apache.org | |
| Oracle Critical Patch Update Advisory - July 2022 | N/A | www.oracle.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 20257 Oracle Database 21c Critical Patch Update - April 2022
- 20270 Oracle Database 21c Critical Patch Update - October 2022
- 20271 Oracle Database 19c Critical Patch Update - October 2022
- 20272 Oracle Database 19c Critical OJVM Patch Update - October 2022
- 239885 Red Hat Update for JBoss Enterprise Application Platform 7.4.2 on RHEL 8 (RHSA-2021:4677)
- 239888 Red Hat Update for JBoss Enterprise Application Platform 7.4.2 on RHEL 7 (RHSA-2021:4676)
- 981829 Java (maven) Security Update for org.apache.sshd:sshd-core (GHSA-9279-7hph-r3xw)