Severity
5.3MEDIUM
EPSS
4.2%
top 11.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 24
Latest updateAug 25

Description

A flaw was found in AMQ Broker. This issue can cause a partial interruption to the availability of AMQ Broker via an Out of memory (OOM) condition. This flaw allows an attacker to partially disrupt availability to the broker through a sustained attack of maliciously crafted messages. The highest threat from this vulnerability is system availability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 3.9 | Impact: 1.4

Affected Packages4 packages

NVDredhat/amq_broker< 7.10.0
CVEListV5amq_brokerFixed in v2.19.1, v2.20.0

Patches

🔴Vulnerability Details

3
GHSA
org.apache.activemq:artemis-core-client Vulnerable to Out-of-Bounds Write2022-08-25
OSV
org.apache.activemq:artemis-core-client Vulnerable to Out-of-Bounds Write2022-08-25
CVEList
CVE-2021-4040: A flaw was found in AMQ Broker2022-08-24

📋Vendor Advisories

1
Red Hat
Broker: Malformed message can result in partial DoS (OOM)2021-11-19
CVE-2021-4040 (MEDIUM CVSS 5.3) | A flaw was found in AMQ Broker | cvebase.io