CVE-2020-14340

MEDIUMCVSS 5.9/10EPSS 2.22%

Last modified

CVE-2020-14340 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles between garbage collection cycles. It may allow the attacker to cause a denial of service. EPSS estimates a 2.22% chance of exploitation in the next 30 days.

Description

A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles between garbage collection cycles. It may allow the attacker to cause a denial of service. It affects XNIO versions 3.6.0.Beta1 through 3.8.1.Final.

Metrics

CVSS 3.1
5.9/10

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Probability
2.22%

80.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
RedhatXnio>= 3.6.1, < 3.7.9
RedhatXnio>= 3.8.0, < 3.8.2
RedhatXnio3.6.0Beta1
RedhatJboss Brms5
RedhatJboss Brms6
RedhatJboss Data Grid6.0.0
RedhatJboss Data Grid7.0.0
RedhatJboss Data Virtualization6.0.0
RedhatJboss Enterprise Application Platform5.0.0
RedhatJboss Enterprise Application Platform6.0.0
RedhatJboss Fuse6.0.0
RedhatJboss Fuse7.0.0
RedhatJboss Operations Network3.0
RedhatJboss Soa Platform5
OracleCommunications Cloud Native Core Console1.9.0
OracleCommunications Cloud Native Core Network Repository Function1.14.0
OracleCommunications Cloud Native Core Policy1.14.0
OracleCommunications Cloud Native Core Security Edge Protection Proxy1.15.0
OracleCommunications Cloud Native Core Service Communication Proxy1.14.0
OracleCommunications Cloud Native Core Unified Data Repository1.14.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-14340?
A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles between garbage collection cycles. It may allow the attacker to cause a denial of service. It affects XNIO versions 3.6.0.Beta1 through 3.8.1.Final.
How severe is CVE-2020-14340?
CVE-2020-14340 has a CVSS score of 5.9/10 (MEDIUM severity). The EPSS model estimates a 2.22% probability of exploitation in the next 30 days.
How do I fix CVE-2020-14340?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-14340?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST