GHSA-gc96-h5pr-839j

Suggest an improvement
Source
https://github.com/advisories/GHSA-gc96-h5pr-839j
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-gc96-h5pr-839j/GHSA-gc96-h5pr-839j.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-gc96-h5pr-839j
Aliases
Published
2022-05-13T01:11:53Z
Modified
2023-11-01T04:47:34.352138Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Uncontrolled Resource Consumption in Artemis and HornetQ
Details

It was found that when Artemis and HornetQ before 2.4.0 are configured with UDP discovery and JGroups discovery a huge byte array is created when receiving an unexpected multicast message. This may result in a heap memory exhaustion, full GC, or OutOfMemoryError.

References

Affected packages

Maven / org.hornetq:hornetq-server

Package

Name
org.hornetq:hornetq-server
View open source insights on deps.dev
Purl
pkg:maven/org.hornetq/hornetq-server

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.0.Final

Affected versions

2.*

2.3.0.BETA2
2.3.0.BETA3
2.3.0.CR1
2.3.0.CR2
2.3.0.Final
2.3.1.Final
2.3.2.Final
2.3.3.Final
2.3.4.Final
2.3.5.Final
2.3.6.Final
2.3.7.Final
2.3.8.Final
2.3.9.Final
2.3.10.Final
2.3.11.Final
2.3.12.Final
2.3.13.Final
2.3.15.Final
2.3.17.Final
2.3.18.Final
2.3.19.Final
2.3.22.Final
2.3.23.Final
2.3.24.Final
2.3.25.Final
2.4.0.Alpha1
2.4.0.Beta1
2.4.0.Beta2
2.4.0.Beta3

Database specific

{
    "last_known_affected_version_range": "<= 2.4.0.Beta3"
}

Maven / org.apache.activemq:artemis-native

Package

Name
org.apache.activemq:artemis-native
View open source insights on deps.dev
Purl
pkg:maven/org.apache.activemq/artemis-native

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.0

Affected versions

1.*

1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6

2.*

2.0.0
2.1.0
2.2.0
2.3.0