PT-2021-5289 · Apache+3 · Apache Tomcat+3

Published

2021-10-06

·

Updated

2025-07-11

·

CVE-2021-42340

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 8.5.60 through 8.5.71 Apache Tomcat versions 9.0.40 through 9.0.53 Apache Tomcat versions 10.0.0-M1 through 10.0.11 Apache Tomcat versions 10.1.0-M1 through 10.1.0-M5
Description The issue is related to a memory leak in Apache Tomcat. This memory leak was introduced by the fix for bug 63362 and occurs because the object used to collect metrics for HTTP upgrade connections is not released for WebSocket connections once the connection is closed. Over time, this can lead to a denial of service via an OutOfMemoryError.
Recommendations For Apache Tomcat versions 8.5.60 through 8.5.71, update to a version that includes the fix for the memory leak. For Apache Tomcat versions 9.0.40 through 9.0.53, update to a version that includes the fix for the memory leak. For Apache Tomcat versions 10.0.0-M1 through 10.0.11, update to a version that includes the fix for the memory leak. For Apache Tomcat versions 10.1.0-M1 through 10.1.0-M5, update to a version that includes the fix for the memory leak. As a temporary workaround, consider restricting the use of WebSocket connections to minimize the risk of exploitation.

Exploit

Fix

DoS

Missing Release of Resource after Effective Lifetime

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2165
ALT-PU-2022-3296
ALT-PU-2025-9146
BDU:2021-06115
BIT-TOMCAT-2021-42340
CVE-2021-42340
DSA-5009-1
GHSA-WPH7-X527-W3H5
INFBA-2022_8077
MGASA-2021-0485
OESA-2021-1413
RHSA-2021:4861
ROSA-SA-2023-2258

Affected Products

Alt Linux
Apache Tomcat
Astra Linux
Red Os