logo

CVE-2018-8030 org.apache.qpid:apache-qpid-broker-j

Package

Manager: maven
Name: org.apache.qpid:apache-qpid-broker-j
Vulnerable Version: >=7.0.0 <7.1.0

Severity

Level: High

CVSS v3.1: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

EPSS: 0.00906 pctl0.74876

Details

Denial of service vulnerability exists when .NET and .NET Core improperly process XML documents A Denial of Service vulnerability was found in Apache Qpid Broker-J versions 7.x before 7.1.0 when AMQP protocols 0-8, 0-9 or 0-91 are used to publish messages with size greater than allowed maximum message size limit (100MB by default). The broker crashes due to the defect. AMQP protocols 0-10 and 1.0 are not affected.

Metadata

Created: 2018-10-16T19:50:39Z
Modified: 2024-03-04T23:40:34Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-7xr3-rgwh-pw22/GHSA-7xr3-rgwh-pw22.json
CWE IDs: ["CWE-20"]
Alternative ID: GHSA-7xr3-rgwh-pw22
Finding: F184
Auto approve: 1