Openwsman, versions up to and including 2.6.9, are vulnerable to infinite loop in process_connection() when parsing specially crafted HTTP requests. A remote, unauthenticated attacker can exploit this vulnerability by sending malicious HTTP request to cause denial of service to openwsman server.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade libwsman-develUpgrade openwsman-serverUpgrade openwsman-clientUpgrade openwsman-python3Upgrade libwsman1 | May 4, 2022 | Mar 14, 2019 |
| Amazon Linux Ami 2 | — | Upgrade openwsman-debuginfoUpgrade openwsman-perlUpgrade openwsman-rubyUpgrade openwsman-serverUpgrade openwsman-pythonUpgrade openwsman-clientUpgrade libwsman1Upgrade libwsman-devel | Oct 28, 2020 | Mar 14, 2019 |
| Centos_linux | — | Upgrade openwsman-python3-debuginfoUpgrade openwsman-perlUpgrade openwsman-client-debuginfoUpgrade libwsman1-debuginfoUpgrade openwsman-pythonUpgrade openwsman-debuginfoUpgrade openwsman-debugsourceUpgrade libwsman1Upgrade libwsman-develUpgrade openwsman-serverUpgrade rubygem-openwsman-debuginfoUpgrade openwsman-rubyUpgrade openwsman-python3Upgrade openwsman-perl-debuginfoUpgrade openwsman-server-debuginfoUpgrade openwsman-client | Oct 1, 2020 | Mar 14, 2019 |
| Huawei Euleros 2_0_sp5 | — | Upgrade libwsman1Upgrade openwsman-pythonUpgrade openwsman-clientUpgrade openwsman-server | Nov 19, 2019 | Mar 14, 2019 |
| Oracle_linux | — | Upgrade openwsman-python3Upgrade libwsman1Upgrade openwsman-perlUpgrade openwsman-pythonUpgrade openwsman-rubyUpgrade openwsman-clientUpgrade openwsman-serverUpgrade libwsman-devel | Oct 7, 2020 | Mar 12, 2019 |
| Redhat_linux | — | Upgrade openwsman-python3Upgrade rubygem-openwsman-debuginfoUpgrade openwsman-client-debuginfoUpgrade openwsman-debugsourceUpgrade openwsman-perl-debuginfoUpgrade openwsman-perlUpgrade libwsman1Upgrade openwsman-server-debuginfoUpgrade libwsman1-debuginfoUpgrade openwsman-debuginfoUpgrade openwsman-python3-debuginfoUpgrade openwsman-rubyUpgrade openwsman-serverUpgrade openwsman-pythonNo solution existsUpgrade openwsman-clientUpgrade libwsman-devel | Oct 1, 2020 | Mar 14, 2019 |
| Rocky_linux | — | Upgrade openwsman-debuginfoUpgrade openwsman-python3Upgrade openwsman-debugsourceUpgrade libwsman1Upgrade libwsman1-debuginfoUpgrade libwsman-develUpgrade openwsman-python3-debuginfoUpgrade openwsman-client-debuginfoUpgrade openwsman-serverUpgrade openwsman-server-debuginfoUpgrade openwsman-client | Mar 12, 2024 | Mar 14, 2019 |
| Suse | — | Upgrade openwsman-server-plugin-rubyUpgrade libwsman_clientpp1Upgrade openwsman-pythonUpgrade openwsman-perlUpgrade libwsman1Upgrade libwsman-develUpgrade winrsUpgrade libwsman_clientpp-develUpgrade openwsman-ruby-docsUpgrade python3-openwsmanUpgrade openwsman-javaUpgrade openwsman-clientUpgrade openwsman-serverUpgrade openwsman-rubyUpgrade libwsman3 | Mar 19, 2019 | Mar 14, 2019 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Mar 14, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub