VDB
RHSA-2020%3A4923
RHSA-2020%3A4923
PUBLISHED
CVSS 7.5 HIGH
A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. This flaw allows an attacker to cause an Out of memory (OOM) issue, leading to a denial of service. The highest threat from this vulnerability is to system availability.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | EAP 7.3.3 |
Timeline
- Nov 4, 2020 CVE Published
- Mar 18, 2026 CVE Updated
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2020:4923 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=securityPatches&product=appplatform&version=7.3 advisory
- https://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.3/ advisory
- https://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.3/html-single/installation_guide/ advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1885485 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_4923.json advisory
- https://access.redhat.com/security/cve/CVE-2020-25644 advisory
- https://www.cve.org/CVERecord?id=CVE-2020-25644 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-25644 advisory