Описание
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service.
This issue affects Apache Qpid Proton-J: through 0.34.1.
Users are recommended to upgrade to version 0.35.0, which fixes the issue.
A flaw was found in Apache Qpid Proton-J. A remote attacker, without needing to authenticate, could exploit a vulnerability related to unbounded type nesting. This could lead to a StackOverflowError, causing the affected system to become unresponsive and resulting in a denial of service.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat AMQ Broker 7 | amq-broker-bin.zip | Affected | ||
| Red Hat AMQ Broker 7 | amq-broker-maven-repository.zip | Affected | ||
| Red Hat AMQ Clients | proton-j | Affected | ||
| Red Hat build of Apache Camel 4 for Quarkus 3 | proton-j | Affected | ||
| Red Hat build of Apache Camel for Spring Boot 4 | rhaf-camel-for-springboot-maven-repository.zip | Affected | ||
| Red Hat build of Apache Camel for Spring Boot 4 | rhaf-camel-maven-repository.zip | Affected | ||
| Red Hat build of Apache Camel for Spring Boot 4 | rhaf-camel-spring-boot-maven-repository.zip | Affected | ||
| Red Hat build of Quarkus | proton-j | Affected | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | proton-j | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.
A pre-authentication attacker could leverage type nesting to cause a S ...
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.
EPSS
7.5 High
CVSS3