Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q66c-h853-gqw2

Опубликовано: 16 окт. 2018
Источник: github
Github: Прошло ревью
CVSS3: 9.1

Описание

AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication

The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication and consequently perform actions via vectors related to connection state logging.

Пакеты

Наименование

org.apache.qpid:qpid-broker-plugins-amqp-0-8-protocol

maven
Затронутые версииВерсия исправления

< 6.0.3

6.0.3

Наименование

org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol

maven
Затронутые версииВерсия исправления

< 6.0.3

6.0.3

EPSS

Процентиль: 60%
0.0039
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 9.1
ubuntu
больше 9 лет назад

The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication and consequently perform actions via vectors related to connection state logging.

redhat
больше 9 лет назад

The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication and consequently perform actions via vectors related to connection state logging.

CVSS3: 9.1
nvd
больше 9 лет назад

The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication and consequently perform actions via vectors related to connection state logging.

CVSS3: 9.1
debian
больше 9 лет назад

The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid J ...

EPSS

Процентиль: 60%
0.0039
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-287