CVE-2021-20318
published 2021-12-23CVE-2021-20318: The HornetQ component of Artemis in EAP 7 was not updated with the fix for CVE-2016-4978. A remote attacker could use this flaw to execute arbitrary code with…
PriorityP344high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
1.70%
74.6th percentile
The HornetQ component of Artemis in EAP 7 was not updated with the fix for CVE-2016-4978. A remote attacker could use this flaw to execute arbitrary code with the permissions of the application using a JMS ObjectMessage.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
7: Incomplete fix of CVE-2016-4978 in HornetQ library
vendor_redhat·2021-10-05·CVSS 7.2
CVE-2021-20318 [HIGH] CWE-502 7: Incomplete fix of CVE-2016-4978 in HornetQ library
7: Incomplete fix of CVE-2016-4978 in HornetQ library
The HornetQ component of Artemis in EAP 7 was not updated with the fix for CVE-2016-4978. A remote attacker could use this flaw to execute arbitrary code with the permissions of the application using a JMS ObjectMessage.
The HornetQ component of Artemis in EAP 7 was not updated with the fix for CVE-2016-4978. A remote attacker could use this flaw to execute arbitrary code with the permissions of the application using a JMS ObjectMessage.
GHSA
GHSA-36vx-8x4w-9h2m: The HornetQ component of Artemis in EAP 7 was not updated with the fix for CVE-2016-4978
ghsa_unreviewed·2021-12-24·CVSS 7.2
CVE-2021-20318 [HIGH] CWE-502 GHSA-36vx-8x4w-9h2m: The HornetQ component of Artemis in EAP 7 was not updated with the fix for CVE-2016-4978
The HornetQ component of Artemis in EAP 7 was not updated with the fix for CVE-2016-4978. A remote attacker could use this flaw to execute arbitrary code with the permissions of the application using a JMS ObjectMessage.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-12-23
Published