CVE-2018-8030
Dashboard / Vulnerabilities / CVE-2018-8030
Summary:
Details: A Denial of Service vulnerability was found in Apache Qpid Broker-J versions 7.0.0-7.0.4 when AMQP protocols 0-8, 0-9 or 0-91 are used to publish messages with size greater than allowed maximum message size limit (100MB by default). The broker crashes due to the defect. AMQP protocols 0-10 and 1.0 are not affected.
References: https://lists.apache.org/thread.html/1089a4f351a1bdca0618199e53bceeec59a10bf4e3008018d6949876%40%3Cusers.qpid.apache.org%3E, http://www.securitytracker.com/id/1041138
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- 82dc87ec35d0ac3f86c0d57e323a7083be771c23
Fixed -None
Affected versions
7.0.4
7.0.3
7.0.2
7.0.1
7.0.0
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
