Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jj9h-mwhq-8vhm

Опубликовано: 16 окт. 2018
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

Improper Input Validation in org.apache.qpid:qpid-broker

PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a denial of service (broker termination) via a crafted authentication attempt, which triggers an uncaught exception.

Пакеты

Наименование

org.apache.qpid:qpid-broker

maven
Затронутые версииВерсия исправления

< 6.0.3

6.0.3

EPSS

Процентиль: 76%
0.00989
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-20
CWE-287

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 9 лет назад

PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a denial of service (broker termination) via a crafted authentication attempt, which triggers an uncaught exception.

redhat
больше 9 лет назад

PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a denial of service (broker termination) via a crafted authentication attempt, which triggers an uncaught exception.

CVSS3: 5.9
nvd
больше 9 лет назад

PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a denial of service (broker termination) via a crafted authentication attempt, which triggers an uncaught exception.

CVSS3: 5.9
debian
больше 9 лет назад

PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker ...

EPSS

Процентиль: 76%
0.00989
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-20
CWE-287