Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-22569

Опубликовано: 06 янв. 2022
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated pauses. We recommend upgrading libraries beyond the vulnerable versions.

A flaw was found in protobuf-java. Google Protocol Buffer (protobuf-java) allows the interleaving of com.google.protobuf.UnknownFieldSet fields. By persuading a victim to open specially-crafted content, a remote attacker could cause a timeout in the ProtobufFuzzer function, resulting in a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch6-rhel8Will not fix
Red Hat BPM Suite 6protobuf-javaOut of support scope
Red Hat build of Debezium 1protobuf-javaAffected
Red Hat CodeReady Studio 12protobuf-javaWill not fix
Red Hat Integration Camel K 1protobuf-javaAffected
Red Hat Integration Service Registryprotobuf-javaAffected
Red Hat JBoss BRMS 5protobuf-javaOut of support scope
Red Hat JBoss BRMS 6protobuf-javaOut of support scope
Red Hat JBoss Data Grid 6protobuf-javaOut of support scope
Red Hat JBoss Data Grid 7protobuf-javaOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-696
https://bugzilla.redhat.com/show_bug.cgi?id=2039903protobuf-java: potential DoS in the parsing procedure for binary data

EPSS

Процентиль: 52%
0.00291
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 4 лет назад

An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated pauses. We recommend upgrading libraries beyond the vulnerable versions.

CVSS3: 7.5
nvd
около 4 лет назад

An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated pauses. We recommend upgrading libraries beyond the vulnerable versions.

CVSS3: 5.5
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 7.5
debian
около 4 лет назад

An issue in protobuf-java allowed the interleaving of com.google.proto ...

CVSS3: 7.5
github
около 4 лет назад

A potential Denial of Service issue in protobuf-java

EPSS

Процентиль: 52%
0.00291
Низкий

5.5 Medium

CVSS3