VDB
RHSA-2020%3A4978
RHSA-2020%3A4978
PUBLISHED
CVSS 7.5 HIGH
A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. This flaw allows an attacker to cause an Out of memory (OOM) issue, leading to a denial of service. The highest threat from this vulnerability is to system availability.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Single Sign-On 7.4.3 one-off |
Timeline
- Nov 9, 2020 CVE Published
- Mar 18, 2026 CVE Updated
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2020:4978 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=securityPatches&product=core.service.rhsso&version=7.4 advisory
- https://access.redhat.com/documentation/en-us/red_hat_single_sign-on/7.4/ advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1885485 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_4978.json advisory
- https://access.redhat.com/security/cve/CVE-2020-25644 advisory
- https://www.cve.org/CVERecord?id=CVE-2020-25644 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-25644 advisory