CVE-2021-41973

Source
https://nvd.nist.gov/vuln/detail/CVE-2021-41973
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-41973.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-41973
Aliases
Published
2021-11-01T09:15:09Z
Modified
2024-09-03T03:56:25.830387Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the beginning of the buffer and loops if there is more data than expected. Please update MINA to 2.1.5 or greater.

References

Affected packages

Git / github.com/apache/mina

Affected ranges

Type
GIT
Repo
https://github.com/apache/mina
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

2.*

2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.20
2.0.21
2.0.8
2.0.9