GHSA-7xr3-rgwh-pw22

    Dashboard / Vulnerabilities / GHSA-7xr3-rgwh-pw22

    GHSA-7xr3-rgwh-pw22

    Published: 16 Oct 2018Last Modified: 4 Mar 2024
    Aliases:

    Summary: Denial of service vulnerability exists when .NET and .NET Core improperly process XML documents

    Details: A Denial of Service vulnerability was found in Apache Qpid Broker-J versions 7.x before 7.1.0 when AMQP protocols 0-8, 0-9 or 0-91 are used to publish messages with size greater than allowed maximum message size limit (100MB by default). The broker crashes due to the defect. AMQP protocols 0-10 and 1.0 are not affected.

    Affected packages

    Package

    Name: org.apache.qpid:apache-qpid-broker-j

    Purl: pkg:maven/org.apache.qpid/apache-qpid-broker-j

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 7.0.0
    Fixed -7.1.0

    Affected versions

    7.0.0
    7.0.1
    7.0.2
    7.0.3
    7.0.4
    7.0.5
    7.0.6
    7.0.7
    7.0.8
    7.0.9

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High