Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-40155

Опубликовано: 16 сент. 2022
Источник: redhat
CVSS3: 7.5

Описание

A flaw was found in the XStream package. This flaw allows an attacker to cause a denial of service (DoS) in its target via XML serialization.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Clients 2xstreamNot affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch6-rhel8Not affected
Migration Toolkit for RuntimesxstreamNot affected
OpenShift Developer Tools and ServicesjenkinsWill not fix
Red Hat AMQ Broker 7xstreamNot affected
Red Hat build of Apache Camel for Spring Boot 3xstreamNot affected
Red Hat build of Apicurio Registry 2xstreamNot affected
Red Hat build of Debezium 1xstreamNot affected
Red Hat build of QuarkusxstreamNot affected
Red Hat Data Grid 8xstreamNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2134289xstream: Xstream to serialise XML data was vulnerable to Denial of Service attacks

7.5 High

CVSS3

Связанные уязвимости

ubuntu
больше 3 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. All references and descriptions in this candidate have been removed to prevent accidental usage.

nvd
больше 3 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. All references and descriptions in this candidate have been removed to prevent accidental usage.

github
больше 3 лет назад

Denial of Service via stack overflow

7.5 High

CVSS3