CVE-2021-30129
Last modified
CVE-2021-30129 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error. This issue affects the SFTP and port forwarding features of Apache Mina SSHD version 2.0.0 and later versions. EPSS estimates a 3.39% chance of exploitation in the next 30 days.
Description
A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error. This issue affects the SFTP and port forwarding features of Apache Mina SSHD version 2.0.0 and later versions. It was addressed in Apache Mina SSHD 2.7.0
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Sshd | >= 2.0.0, < 2.7.0 |
| Oracle | Banking Payments | 14.5 |
| Oracle | Banking Trade Finance | 14.5 |
| Oracle | Banking Treasury Management | 14.5 |
| Oracle | Communications Cloud Native Core Console | 1.9.0 |
| Oracle | Flexcube Universal Banking | >= 14.0.0, <= 14.3.0 |
| Oracle | Flexcube Universal Banking | 14.5 |
| Oracle | Middleware Common Libraries And Tools | 12.2.1.3.0 |
| Oracle | Middleware Common Libraries And Tools | 12.2.1.4.0 |
| Oracle | Middleware Common Libraries And Tools | 14.1.1.0.0 |
| Oracle | Oss Support Tools | 2.12.42 |
| Oracle | Retail Customer Management And Segmentation Foundation | 18.0 |
| Oracle | Retail Customer Management And Segmentation Foundation | 19.0 |
References
- http://www.openwall.com/lists/oss-security/2021/07/12/1Mailing List, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/07/12/1Mailing List, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-30129?
How severe is CVE-2021-30129?
How do I fix CVE-2021-30129?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-30123FFmpeg <=4.3 contains a buffer overflow vulnerability in lib…8.8
- CVE-2021-30124The unofficial vscode-phpmd (aka PHP Mess Detector) extensio…9.8
- CVE-2021-30125Jamf Pro before 10.28.0 allows XSS related to inventory hist…6.1
- CVE-2021-30126Lightmeter ControlCenter 1.1.0 through 1.5.x before 1.5.1 al…6.5
- CVE-2021-30127TerraMaster F2-210 devices through 2021-04-03 use UPnP to ma…7.3
- CVE-2021-30128Apache OFBiz has unsafe deserialization prior to 17.12.07 ve…9.8
- CVE-2021-3013ripgrep before 13 on Windows allows attackers to trigger exe…9.8
- CVE-2021-30130phpseclib before 2.0.31 and 3.x before 3.0.7 mishandles RSA …7.5
- CVE-2021-30132Cloudera Manager 7.2.4 has Incorrect Access Control, allowin…9.8
- CVE-2021-30133A cross-site scripting (XSS) vulnerability in CloverDX Serve…6.1
- CVE-2021-30134php-mod/curl (a wrapper of the PHP cURL extension) before 2.…6.1
- CVE-2021-30137Assyst 10 SP7.5 has authenticated XXE leading to SSRF via XM…8.2
Are you affected by CVE-2021-30129?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
