Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q66c-h853-gqw2

Опубликовано: 16 окт. 2018
Источник: github
Github: Прошло ревью
CVSS3: 9.1

Описание

AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication

The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication and consequently perform actions via vectors related to connection state logging.

Пакеты

Наименование

org.apache.qpid:qpid-broker-plugins-amqp-0-8-protocol

maven
Затронутые версииВерсия исправления

< 6.0.3

6.0.3

Наименование

org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol

maven
Затронутые версииВерсия исправления

< 6.0.3

6.0.3

EPSS

Процентиль: 94%
0.08148
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 9.1
ubuntu
больше 10 лет назад

The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication and consequently perform actions via vectors related to connection state logging.

redhat
больше 10 лет назад

The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication and consequently perform actions via vectors related to connection state logging.

CVSS3: 9.1
nvd
больше 10 лет назад

The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication and consequently perform actions via vectors related to connection state logging.

CVSS3: 9.1
debian
больше 10 лет назад

The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid J ...

EPSS

Процентиль: 94%
0.08148
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-287