[seam-issues] [JBoss JIRA] (SOLDER-340) Memory Leak during DOS Attack using OWASP DirBuster

James Livingston (JIRA) issues at jboss.org
Wed Oct 7 19:25:00 EDT 2015


    [ https://issues.jboss.org/browse/SOLDER-340?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13116206#comment-13116206 ] 

James Livingston commented on SOLDER-340:
-----------------------------------------

WELD-1323 is related to this, and more recent versions of Weld do not have an unbounded cache. Solder should arguably not use non-constant qualifiers though

> Memory Leak during DOS Attack using OWASP DirBuster
> ---------------------------------------------------
>
>                 Key: SOLDER-340
>                 URL: https://issues.jboss.org/browse/SOLDER-340
>             Project: Solder
>          Issue Type: Bug
>          Components: Servlet
>    Affects Versions: 3.2.0.Final
>         Environment: ALL
>            Reporter: Melloware Inc
>            Priority: Critical
>         Attachments: memoryleak.zip
>
>
> During performance testing of our application using OWASP DirBuster to simulate a DOS attack scanning for directories it appears our EAP 6.0.1 leaked memory until the JVM Locked up.   Even after manually attempting a GC the memory stays frozen and does not free up.  



--
This message was sent by Atlassian JIRA
(v6.4.11#64026)


More information about the seam-issues mailing list