QID 981010
QID 981010: Java (maven) Security Update for org.apache.qpid:qpid-broker (GHSA-jj9h-mwhq-8vhm)
PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a denial of service (broker termination) via a crafted authentication attempt, which triggers an uncaught exception.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-jj9h-mwhq-8vhm for updates pertaining to this vulnerability.
Vendor References
- GHSA-jj9h-mwhq-8vhm -
github.com/advisories/GHSA-jj9h-mwhq-8vhm
CVEs related to QID 981010
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-jj9h-mwhq-8vhm | org.apache.qpid:qpid-broker |
|