Openwsman, versions up to and including 2.6.9, are vulnerable to infinite loop in process_connection() when parsing specially crafted HTTP requests. A remote, unauthenticated attacker can exploit this vulnerability by sending malicious HTTP request to cause denial of service to openwsman server.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade openwsman-clientUpgrade openwsman-serverUpgrade openwsman-python3Upgrade libwsman-develUpgrade libwsman1 | May 4, 2022 | Mar 14, 2019 |
| Amazon Linux Ami 2 | — | Upgrade openwsman-rubyUpgrade openwsman-perlUpgrade openwsman-debuginfoUpgrade openwsman-pythonUpgrade libwsman-develUpgrade libwsman1Upgrade openwsman-serverUpgrade openwsman-client | Oct 28, 2020 | Mar 14, 2019 |
| Centos_linux | — | Upgrade libwsman1Upgrade openwsman-client-debuginfoUpgrade openwsman-debuginfoUpgrade openwsman-perlUpgrade libwsman-develUpgrade openwsman-python3-debuginfoUpgrade openwsman-debugsourceUpgrade openwsman-pythonUpgrade libwsman1-debuginfoUpgrade openwsman-server-debuginfoUpgrade openwsman-serverUpgrade openwsman-clientUpgrade openwsman-rubyUpgrade rubygem-openwsman-debuginfoUpgrade openwsman-perl-debuginfoUpgrade openwsman-python3 | Oct 1, 2020 | Mar 14, 2019 |
| Huawei Euleros 2_0_sp5 | — | Upgrade openwsman-serverUpgrade openwsman-clientUpgrade libwsman1Upgrade openwsman-python | Nov 19, 2019 | Mar 14, 2019 |
| Oracle_linux | — | Upgrade openwsman-rubyUpgrade openwsman-serverUpgrade libwsman-develUpgrade openwsman-clientUpgrade openwsman-python3Upgrade openwsman-pythonUpgrade openwsman-perlUpgrade libwsman1 | Oct 7, 2020 | Mar 12, 2019 |
| Redhat_linux | — | Upgrade openwsman-python3-debuginfoUpgrade libwsman1-debuginfoUpgrade libwsman-develNo solution existsUpgrade openwsman-debuginfoUpgrade openwsman-clientUpgrade openwsman-pythonUpgrade openwsman-serverUpgrade openwsman-rubyUpgrade openwsman-debugsourceUpgrade openwsman-perlUpgrade openwsman-python3Upgrade libwsman1Upgrade openwsman-server-debuginfoUpgrade rubygem-openwsman-debuginfoUpgrade openwsman-client-debuginfoUpgrade openwsman-perl-debuginfo | Oct 1, 2020 | Mar 14, 2019 |
| Rocky_linux | — | Upgrade openwsman-client-debuginfoUpgrade openwsman-python3Upgrade openwsman-python3-debuginfoUpgrade openwsman-debuginfoUpgrade libwsman1Upgrade libwsman1-debuginfoUpgrade openwsman-debugsourceUpgrade libwsman-develUpgrade openwsman-server-debuginfoUpgrade openwsman-serverUpgrade openwsman-client | Mar 12, 2024 | Mar 14, 2019 |
| Suse | — | Upgrade openwsman-javaUpgrade openwsman-clientUpgrade openwsman-serverUpgrade libwsman3Upgrade openwsman-rubyUpgrade libwsman-develUpgrade winrsUpgrade libwsman1Upgrade python3-openwsmanUpgrade openwsman-server-plugin-rubyUpgrade openwsman-pythonUpgrade libwsman_clientpp-develUpgrade libwsman_clientpp1Upgrade openwsman-ruby-docsUpgrade openwsman-perl | Mar 19, 2019 | Mar 14, 2019 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Mar 14, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub