Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-whxr-3p84-rf3c

Опубликовано: 07 мая 2025
Источник: github
Github: Прошло ревью
CVSS4: 6.9
CVSS3: 7.5

Описание

Apache ActiveMQ: Unchecked buffer length can cause excessive memory allocation

Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ.

During unmarshalling of OpenWire commands the size value of buffers was not properly validated which could lead to excessive memory allocation and be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services that rely on the availability of the ActiveMQ broker when not using mutual TLS connections. This issue affects Apache ActiveMQ: from 6.0.0 before 6.1.6, from 5.18.0 before 5.18.7, from 5.17.0 before 5.17.7, before 5.16.8. ActiveMQ 5.19.0 is not affected.

Users are recommended to upgrade to version 6.1.6+, 5.19.0+, 5.18.7+, 5.17.7, or 5.16.8 or which fixes the issue.

Existing users may implement mutual TLS to mitigate the risk on affected brokers.

Пакеты

Наименование

org.apache.activemq:activemq-openwire-legacy

maven
Затронутые версииВерсия исправления

< 5.16.8

5.16.8

Наименование

org.apache.activemq:activemq-client

maven
Затронутые версииВерсия исправления

< 5.16.8

5.16.8

Наименование

org.apache.activemq:activemq-openwire-legacy

maven
Затронутые версииВерсия исправления

>= 5.17.0, < 5.17.7

5.17.7

Наименование

org.apache.activemq:activemq-openwire-legacy

maven
Затронутые версииВерсия исправления

>= 5.18.0, < 5.18.7

5.18.7

Наименование

org.apache.activemq:activemq-openwire-legacy

maven
Затронутые версииВерсия исправления

>= 6.0.0, < 6.1.6

6.1.6

Наименование

org.apache.activemq:activemq-client

maven
Затронутые версииВерсия исправления

>= 5.17.0, < 5.17.7

5.17.7

Наименование

org.apache.activemq:activemq-client

maven
Затронутые версииВерсия исправления

>= 5.18.0, < 5.18.7

5.18.7

Наименование

org.apache.activemq:activemq-client

maven
Затронутые версииВерсия исправления

>= 6.0.0, < 6.1.6

6.1.6

EPSS

Процентиль: 66%
0.00533
Низкий

6.9 Medium

CVSS4

7.5 High

CVSS3

Дефекты

CWE-789

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ. During unmarshalling of OpenWire commands the size value of buffers was not properly validated which could lead to excessive memory allocation and be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services that rely on the availability of the ActiveMQ broker when not using mutual TLS connections. This issue affects Apache ActiveMQ: from 6.0.0 before 6.1.6, from 5.18.0 before 5.18.7, from 5.17.0 before 5.17.7, before 5.16.8. ActiveMQ 5.19.0 is not affected. Users are recommended to upgrade to version 6.1.6+, 5.19.0+, 5.18.7+, 5.17.7, or 5.16.8 or which fixes the issue. Existing users may implement mutual TLS to mitigate the risk on affected brokers.

CVSS3: 4.9
redhat
4 месяца назад

Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ. During unmarshalling of OpenWire commands the size value of buffers was not properly validated which could lead to excessive memory allocation and be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services that rely on the availability of the ActiveMQ broker when not using mutual TLS connections. This issue affects Apache ActiveMQ: from 6.0.0 before 6.1.6, from 5.18.0 before 5.18.7, from 5.17.0 before 5.17.7, before 5.16.8. ActiveMQ 5.19.0 is not affected. Users are recommended to upgrade to version 6.1.6+, 5.19.0+, 5.18.7+, 5.17.7, or 5.16.8 or which fixes the issue. Existing users may implement mutual TLS to mitigate the risk on affected brokers.

CVSS3: 7.5
nvd
4 месяца назад

Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ. During unmarshalling of OpenWire commands the size value of buffers was not properly validated which could lead to excessive memory allocation and be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services that rely on the availability of the ActiveMQ broker when not using mutual TLS connections. This issue affects Apache ActiveMQ: from 6.0.0 before 6.1.6, from 5.18.0 before 5.18.7, from 5.17.0 before 5.17.7, before 5.16.8. ActiveMQ 5.19.0 is not affected. Users are recommended to upgrade to version 6.1.6+, 5.19.0+, 5.18.7+, 5.17.7, or 5.16.8 or which fixes the issue. Existing users may implement mutual TLS to mitigate the risk on affected brokers.

CVSS3: 7.5
debian
4 месяца назад

Memory Allocation with Excessive Size Value vulnerability in Apache Ac ...

CVSS3: 6.8
fstec
4 месяца назад

Уязвимость обработчика команд OpenWire программной платформы Apache ActiveMQ, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 66%
0.00533
Низкий

6.9 Medium

CVSS4

7.5 High

CVSS3

Дефекты

CWE-789