{"id":"CVE-2020-25644","aliases":[],"url":"https://o3.security/vulnerability/CVE-2020-25644","summary":"Wildfly-OpenSSL memory leak flaw","details":"A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM leading to a denial of service. The highest threat from this vulnerability is to system availability.","published":"2022-05-24T17:30:10Z","modified":"2024-02-22T01:45:33Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.wildfly.openssl:wildfly-openssl-natives-parent","fixedVersion":"1.1.3.Final"}],"fix":{"url":"https://github.com/wildfly-security/wildfly-openssl-natives/pull/4","label":"wildfly-security/wildfly-openssl-natives#4"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-25644"},{"type":"WEB","url":"https://github.com/wildfly-security/wildfly-openssl-natives/pull/4"},{"type":"WEB","url":"https://github.com/wildfly-security/wildfly-openssl-natives/pull/4/files"},{"type":"WEB","url":"https://github.com/wildfly-security/wildfly-openssl-natives/commit/7c26514676f3fb0dee0bcaa7d4680f982372950f"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1885485"},{"type":"PACKAGE","url":"https://github.com/wildfly-security/wildfly-openssl-natives"},{"type":"WEB","url":"https://issues.redhat.com/browse/WFSSL-51"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20201016-0004"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-02-22T01:45:33Z"}}