CVE-2017-15701
published 2017-12-01CVE-2017-15701: In Apache Qpid Broker-J versions 6.1.0 through 6.1.4 (inclusive) the broker does not properly enforce a maximum frame size in AMQP 1.0 frames. A remote…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
4.39%
90.2th percentile
In Apache Qpid Broker-J versions 6.1.0 through 6.1.4 (inclusive) the broker does not properly enforce a maximum frame size in AMQP 1.0 frames. A remote unauthenticated attacker could exploit this to cause the broker to exhaust all available memory and eventually terminate. Older AMQP protocols are not affected.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | qpid_broker-j | 6.1.0 – 6.1.4 | — |
| apache_software_foundation | apache_qpid_broker-j | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache Qpid Broker-J vulnerable to Denial of Service (DoS) via uncontrolled resource consumption
ghsa·2018-10-19
CVE-2017-15701 [HIGH] CWE-400 Apache Qpid Broker-J vulnerable to Denial of Service (DoS) via uncontrolled resource consumption
Apache Qpid Broker-J vulnerable to Denial of Service (DoS) via uncontrolled resource consumption
In Apache Qpid Broker-J versions 6.1.0 through 6.1.4 (inclusive) the broker does not properly enforce a maximum frame size in AMQP 1.0 frames. A remote unauthenticated attacker could exploit this to cause the broker to exhaust all available memory and eventually terminate. Older AMQP protocols are not affected.
OSV
Apache Qpid Broker-J vulnerable to Denial of Service (DoS) via uncontrolled resource consumption
osv·2018-10-19
CVE-2017-15701 [HIGH] Apache Qpid Broker-J vulnerable to Denial of Service (DoS) via uncontrolled resource consumption
Apache Qpid Broker-J vulnerable to Denial of Service (DoS) via uncontrolled resource consumption
In Apache Qpid Broker-J versions 6.1.0 through 6.1.4 (inclusive) the broker does not properly enforce a maximum frame size in AMQP 1.0 frames. A remote unauthenticated attacker could exploit this to cause the broker to exhaust all available memory and eventually terminate. Older AMQP protocols are not affected.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/102041https://issues.apache.org/jira/browse/QPID-7947https://lists.apache.org/thread.html/4054e1c90993f337eeea24a312841c0661653e673c0ff8e2cd9520fe%40%3Cdev.qpid.apache.org%3Ehttps://qpid.apache.org/cves/CVE-2017-15701.htmlhttp://www.securityfocus.com/bid/102041https://issues.apache.org/jira/browse/QPID-7947https://lists.apache.org/thread.html/4054e1c90993f337eeea24a312841c0661653e673c0ff8e2cd9520fe%40%3Cdev.qpid.apache.org%3Ehttps://qpid.apache.org/cves/CVE-2017-15701.html
2017-12-01
Published