Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p76j-5v6v-6c22

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Apache NiFi JMS Deserialization issue

Apache NiFi JMS Deserialization issue because of ActiveMQ client vulnerability. Malicious JMS content could cause denial of service. See ActiveMQ CVE-2015-5254 announcement for more information. The fix to upgrade the activemq-client library to 5.15.3 was applied on the Apache NiFi 1.6.0 release. Users running a prior 1.x release should upgrade to the appropriate release.

Пакеты

Наименование

org.apache.nifi:nifi

maven
Затронутые версииВерсия исправления

< 1.6.0

1.6.0

EPSS

Процентиль: 81%
0.01625
Низкий

7.5 High

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 7.5
nvd
больше 7 лет назад

Apache NiFi JMS Deserialization issue because of ActiveMQ client vulnerability. Malicious JMS content could cause denial of service. See ActiveMQ CVE-2015-5254 announcement for more information. The fix to upgrade the activemq-client library to 5.15.3 was applied on the Apache NiFi 1.6.0 release. Users running a prior 1.x release should upgrade to the appropriate release.

EPSS

Процентиль: 81%
0.01625
Низкий

7.5 High

CVSS3

Дефекты

CWE-502