CVE-2021-37137
Published on: 10/19/2021 12:00:00 AM UTC
Last Modified on: 02/24/2023 04:16:00 PM UTC
Certain versions of Tinkerpop from Apache contain the following vulnerability:
The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved skippable chunks until the whole chunk was received which may lead to excessive memory usage as well. This vulnerability can be triggered by supplying malicious input that decompresses to a very big size (via a network stream or a file) or by sending a huge skippable chunk.
- CVE-2021-37137 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
The Netty project - Netty version < 4.1.68Final
CVSS3 Score: 7.5 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | NONE | HIGH |
CVSS2 Score: 5 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
NONE | NONE | PARTIAL |
CVE References
Related QID Numbers
- 181469 Debian Security Update for netty (DLA 3268-1)
- 181471 Debian Security Update for netty (DSA 5316-1)
- 240458 Red Hat Update for JBoss Enterprise Application Platform 7.4.5 on RHEL 7 (RHSA-2022:4918)
- 240459 Red Hat Update for JBoss Enterprise Application Platform 7.4.5 on RHEL 8 (RHSA-2022:4919)
- 240925 Red Hat Update for Satellite 6.12 (RHSA-2022:8506)
- 376257 Oracle PeopleSoft Enterprise PeopleTools Product Multiple Vulnerabilities (CPUJAN2022)
- 376549 Oracle Coherence April 2022 Critical Patch Update (CPUAPR2022)
- 960485 Rocky Linux Security Update for Satellite (RLSA-2022:8506)
- 980257 Java (maven) Security Update for io.netty:netty-codec (GHSA-9vjp-v76f-g363)
Exploit/POC from Github
This repository contains a collection of data files on known Common Vulnerabilities and Exposures (CVEs). Each file i…
Known Affected Configurations (CPE V2.3)
- cpe:2.3:a:apache:tinkerpop:3.5.0:*:*:*:*:*:*:*:
- cpe:2.3:a:apache:tinkerpop:3.5.1:*:*:*:*:*:*:*:
- cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*:
- cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*:
- cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*:
- cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:banking_apis:19.1:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:banking_apis:19.2:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:banking_apis:20.1:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:banking_apis:21.1:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:banking_apis:*:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:banking_digital_experience:18.1:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:banking_digital_experience:18.2:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:banking_digital_experience:18.3:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:banking_digital_experience:19.1:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:banking_digital_experience:19.2:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:banking_digital_experience:20.1:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:banking_digital_experience:21.1:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:commerce_guided_search:11.3.2:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_brm_-_elastic_charging_engine:*:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_brm_-_elastic_charging_engine:12.0.0.5.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:1.10.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_diameter_signaling_router:*:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.59:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:webcenter_portal:12.2.1.3.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*:
- cpe:2.3:a:quarkus:quarkus:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2021-37137 : The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive me… twitter.com/i/web/status/1… | 2021-10-19 14:45:13 |