QID 996908
Date Published: 2024-01-29
QID 996908: Java (Maven) Security Update for org.apache.geronimo:geronimo (GHSA-v3h8-rw48-h4gr)
Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters. NOTE: this might overlap CVE-2011-4461.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-v3h8-rw48-h4gr for updates and patch information.
Vendor References
- GHSA-v3h8-rw48-h4gr -
github.com/advisories/GHSA-v3h8-rw48-h4gr
CVEs related to QID 996908
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-v3h8-rw48-h4gr | org.apache.geronimo:geronimo |
|