5.3
CVSSv3

CVE-2021-21419

Published: 07/05/2021 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Eventlet is a concurrent networking library for Python. A websocket peer may exhaust memory on Eventlet side by sending very large websocket frames. Malicious peer may exhaust memory on Eventlet side by sending highly compressed data frame. A patch in version 0.31.0 restricts websocket frame to reasonable limits. As a workaround, restricting memory usage via OS limits would help against overall machine exhaustion, but there is no workaround to protect Eventlet process.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

eventlet eventlet

fedoraproject fedora 33

fedoraproject fedora 34

Vendor Advisories

Synopsis Important: OpenShift Container Platform 41030 bug fix and security update Type/Severity Security Advisory: Important Topic Red Hat OpenShift Container Platform release 41030 is now available withupdates to packages and images that fix several bugs and add enhancementsThis release includes a security update for Red Hat OpenShift ...
Debian Bug report logs - #988342 python-eventlet: CVE-2021-21419 Package: src:python-eventlet; Maintainer for src:python-eventlet is Debian Python Team <team+python@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 10 May 2021 19:27:04 UTC Severity: important Tags: security, upstre ...
A flaw was found in eventlet If an unauthenticated user manages to send large websocket frames or highly compressed data frames that can lead to memory exhaustion An attacker could use this flaw to cause a denial of service (DoS) ...
A security issue was found in python-eventlet before version 0310 A websocket peer may exhaust memory on the Eventlet side by sending very large websocket frames A malicious peer may exhaust memory on the Eventlet side by sending highly compressed data frames A patch in version 0310 restricts websocket frames to reasonable limits As a worka ...