Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-5632

Опубликовано: 18 окт. 2023
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

In Eclipse Mosquito before and including 2.0.5, establishing a connection to the mosquitto server without sending data causes the EPOLLOUT event to be added, which results excessive CPU consumption. This could be used by a malicious actor to perform denial of service type attack. This issue is fixed in 2.0.6

A denial of service vulnerability was found in Eclipse Mosquitto. Establishing a connection to the Mosquitto server without sending data could lead to excessive CPU consumption and a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel for Spring Boot 3mosquittoNot affected
Red Hat Integration Camel K 1mosquittoNot affected
Red Hat Satellite 6mosquittoNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=2244840Mosquitto: Possible Denial of Service due to excessive CPE consumption

EPSS

Процентиль: 26%
0.00091
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

In Eclipse Mosquito before and including 2.0.5, establishing a connection to the mosquitto server without sending data causes the EPOLLOUT event to be added, which results excessive CPU consumption. This could be used by a malicious actor to perform denial of service type attack. This issue is fixed in 2.0.6

CVSS3: 7.5
nvd
больше 2 лет назад

In Eclipse Mosquito before and including 2.0.5, establishing a connection to the mosquitto server without sending data causes the EPOLLOUT event to be added, which results excessive CPU consumption. This could be used by a malicious actor to perform denial of service type attack. This issue is fixed in 2.0.6

CVSS3: 7.5
debian
больше 2 лет назад

In Eclipse Mosquito before and including 2.0.5, establishing a connect ...

CVSS3: 7.5
github
больше 2 лет назад

In Eclipse Mosquito before and including 2.0.5, establishing a connection to the mosquitto server without sending data causes the EPOLLOUT event to be added, which results excessive CPU consumption. This could be used by a malicious actor to perform denial of service type attack. This issue is fixed in 2.0.6

EPSS

Процентиль: 26%
0.00091
Низкий

6.5 Medium

CVSS3