Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f38p-mq64-h784

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Improper Input Validation in Apache Qpid AMQP 0-x JMS

Apache Qpid AMQP 0-x JMS client before 6.0.4 and JMS (AMQP 1.0) before 0.10.0 does not restrict the use of classes available on the classpath, which might allow remote authenticated users with permission to send messages to deserialize arbitrary objects and execute arbitrary code by leveraging a crafted serialized object in a JMS ObjectMessage that is handled by the getObject function.

Пакеты

Наименование

org.apache.qpid:qpid-jms-client

maven
Затронутые версииВерсия исправления

<= 0.9.0

0.10.0

EPSS

Процентиль: 84%
0.02129
Низкий

7.5 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 9 лет назад

Apache Qpid AMQP 0-x JMS client before 6.0.4 and JMS (AMQP 1.0) before 0.10.0 does not restrict the use of classes available on the classpath, which might allow remote authenticated users with permission to send messages to deserialize arbitrary objects and execute arbitrary code by leveraging a crafted serialized object in a JMS ObjectMessage that is handled by the getObject function.

CVSS3: 5.6
redhat
больше 9 лет назад

Apache Qpid AMQP 0-x JMS client before 6.0.4 and JMS (AMQP 1.0) before 0.10.0 does not restrict the use of classes available on the classpath, which might allow remote authenticated users with permission to send messages to deserialize arbitrary objects and execute arbitrary code by leveraging a crafted serialized object in a JMS ObjectMessage that is handled by the getObject function.

CVSS3: 7.5
nvd
больше 9 лет назад

Apache Qpid AMQP 0-x JMS client before 6.0.4 and JMS (AMQP 1.0) before 0.10.0 does not restrict the use of classes available on the classpath, which might allow remote authenticated users with permission to send messages to deserialize arbitrary objects and execute arbitrary code by leveraging a crafted serialized object in a JMS ObjectMessage that is handled by the getObject function.

CVSS3: 7.5
debian
больше 9 лет назад

Apache Qpid AMQP 0-x JMS client before 6.0.4 and JMS (AMQP 1.0) before ...

EPSS

Процентиль: 84%
0.02129
Низкий

7.5 High

CVSS3

Дефекты

CWE-20