Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-25897

Опубликовано: 08 сент. 2022
Источник: redhat
CVSS3: 7.5

Описание

The package org.eclipse.milo:sdk-server before 0.6.8 are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory consumption by sending multiple CloseSession requests with the deleteSubscription parameter equal to False.

A flaw was found in the Eclipse Milo SDK Server. This flaw allows an attacker to consume the application memory, leading to a denial of service by sending specific requests.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7org.eclipse.milo-sdk-serveWill not fix
Red Hat Integration Camel K 1org.eclipse.milo-sdk-serverNot affected
Red Hat Integration Camel Quarkus 1org.eclipse.milo-sdk-serverNot affected
RHINT Camel-Springboot 3.18.3org.eclipse.milo-sdk-serverFixedRHSA-2022:890208.12.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.9
nvd
больше 3 лет назад

The package org.eclipse.milo:sdk-server before 0.6.8 are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory consumption by sending multiple CloseSession requests with the deleteSubscription parameter equal to False.

CVSS3: 7.5
github
больше 3 лет назад

Eclipse Milo vulnerable to Resource Exhaustion (Denial of Service)

7.5 High

CVSS3