Описание
In Stomper 5e2741e when a client sends a SEND frame missing the destination header field, the server triggers a null pointer dereference (or access to invalid memory) while processing the frame, causing the process to crash.
A flaw was found in Stomper. A remote attacker can send a specially crafted message, specifically a SEND frame missing the destination header field, to the server. This action triggers a null pointer dereference, which is an attempt to access memory that does not exist, causing the server process to crash. This vulnerability leads to a Denial of Service (DoS), making the server unavailable to legitimate users.
Отчет
A NULL pointer dereference flaw was found in Stomper. A remote, unauthenticated attacker can exploit this by sending a malformed STOMP SEND frame that omits the required destination header field. When processing the frame, the server attempts to access an invalid memory address, causing the server process to crash immediately. Red Hat default security controls, such as process isolation and non-root execution environments, mitigate the issue by preventing privilege escalation or arbitrary code execution beyond a Denial of Service against the message broker.
Меры по смягчению последствий
Limit exposure by configuring network firewalls or security groups to restrict STOMP server access to trusted clients only. If supported by an intermediate proxy or API gateway, inspect and drop incoming STOMP frames that lack mandatory header fields before they reach the broker.
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
In Stomper 5e2741e when a client sends a SEND frame missing the destination header field, the server triggers a null pointer dereference (or access to invalid memory) while processing the frame, causing the process to crash.
In Stomper 5e2741e when a client sends a SEND frame missing the destination header field, the server triggers a null pointer dereference (or access to invalid memory) while processing the frame, causing the process to crash.
In Stomper 5e2741e when a client sends a SEND frame missing the destination header field, the server triggers a null pointer dereference (or access to invalid memory) while processing the frame, causing the process to crash.
7.5 High
CVSS3