QID 981315
QID 981315: Java (maven) Security Update for org.apache.qpid:qpid-broker (GHSA-4r7g-7cpj-5jr7)
In Apache Qpid Broker-J versions 6.1.0 through 6.1.4 (inclusive) the broker does not properly enforce a maximum frame size in AMQP 1.0 frames. A remote unauthenticated attacker could exploit this to cause the broker to exhaust all available memory and eventually terminate. Older AMQP protocols are not affected.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-4r7g-7cpj-5jr7 for updates pertaining to this vulnerability.
Vendor References
- GHSA-4r7g-7cpj-5jr7 -
github.com/advisories/GHSA-4r7g-7cpj-5jr7
CVEs related to QID 981315
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-4r7g-7cpj-5jr7 | org.apache.qpid:qpid-broker |
|