CVE-2023-3171
published 2023-12-27CVE-2023-3171: A flaw was found in EAP-7 during deserialization of certain classes, which permits instantiation of HashMap and HashTable with no checks on resources consumed…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.85%
54.1th percentile
A flaw was found in EAP-7 during deserialization of certain classes, which permits instantiation of HashMap and HashTable with no checks on resources consumed. This issue could allow an attacker to submit malicious requests using these classes, which could eventually exhaust the heap and result in a Denial of Service.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome_chrome | — | — | |
| redhat | jboss_enterprise_application_platform | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_oracle7.5MEDIUM
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Stable Channel Update for Desktop: CVE-2024-3171
vendor_chrome·2024-02-20·CVSS 5.4
CVE-2024-3171 [MEDIUM] Stable Channel Update for Desktop: CVE-2024-3171
Stable Channel Update for Desktop
CVE-2024-3171: Use after free in Accessibility. Reported by ttt on 2023-12-12 [$1000][ 40944847 ] Low CVE-2024-1676: Inappropriate implementation in Navigation
Reported by Khalil Zhani on 2023-11-21 We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel
Severity: medium
Oracle
Oracle Oracle GoldenGate Risk Matrix: Veridata (Google Protobuf-Java) — CVE-2022-3171
vendor_oracle·2023-10-15·CVSS 6.5
CVE-2022-3171 [MEDIUM] Oracle Oracle GoldenGate Risk Matrix: Veridata (Google Protobuf-Java) — CVE-2022-3171
Oracle Oracle GoldenGate Risk Matrix: Veridata (Google Protobuf-Java) vulnerability
CVE: CVE-2022-3171
CVSS: 6.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Adjacent
Network
Advisory: cpuoct2023 (OCT 2023)
Red Hat
eap-7: heap exhaustion via deserialization
vendor_redhat·2023-10-05·CVSS 7.5
CVE-2023-3171 [HIGH] CWE-789 eap-7: heap exhaustion via deserialization
eap-7: heap exhaustion via deserialization
A flaw was found in EAP-7 during deserialization of certain classes, which permits instantiation of HashMap and HashTable with no checks on resources consumed. This issue could allow an attacker to submit malicious requests using these classes, which could eventually exhaust the heap and result in a Denial of Service.
A flaw was found in EAP-7 during deserialization of certain classes, which permits instantiation of HashMap and HashTable with no checks on resources consumed. This issue could allow an attacker to submit malicious requests using these classes, which could eventually exhaust the heap and result in a Denial of Service.
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Accessibility (Google Protobuf-Java) — CVE-2022-3171
vendor_oracle·2023-07-15·CVSS 7.5
CVE-2022-3171 [MEDIUM] Oracle Oracle Financial Services Applications Risk Matrix: Accessibility (Google Protobuf-Java) — CVE-2022-3171
Oracle Oracle Financial Services Applications Risk Matrix: Accessibility (Google Protobuf-Java) vulnerability
CVE: CVE-2022-3171
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Core (Google Protobuf-Java) — CVE-2022-3171
vendor_oracle·2023-04-15·CVSS 7.5
CVE-2022-3171 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Core (Google Protobuf-Java) — CVE-2022-3171
Oracle Oracle Communications Applications Risk Matrix: Core (Google Protobuf-Java) vulnerability
CVE: CVE-2022-3171
CVSS: 7.5
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Policy (Google Protobuf-Java) — CVE-2022-3171
vendor_oracle·2023-01-15·CVSS 7.5
CVE-2022-3171 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Policy (Google Protobuf-Java) — CVE-2022-3171
Oracle Oracle Communications Applications Risk Matrix: Policy (Google Protobuf-Java) vulnerability
CVE: CVE-2022-3171
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
GHSA
GHSA-gpgq-5q34-mh72: A flaw was found in EAP-7 during deserialization of certain classes, which permits instantiation of HashMap and HashTable with no checks on resources
ghsa_unreviewed·2023-12-27
CVE-2023-3171 [HIGH] CWE-770 GHSA-gpgq-5q34-mh72: A flaw was found in EAP-7 during deserialization of certain classes, which permits instantiation of HashMap and HashTable with no checks on resources
A flaw was found in EAP-7 during deserialization of certain classes, which permits instantiation of HashMap and HashTable with no checks on resources consumed. This issue could allow an attacker to submit malicious requests using these classes, which could eventually exhaust the heap and result in a Denial of Service.
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2023:5484https://access.redhat.com/errata/RHSA-2023:5485https://access.redhat.com/errata/RHSA-2023:5486https://access.redhat.com/errata/RHSA-2023:5488https://access.redhat.com/security/cve/CVE-2023-3171https://bugzilla.redhat.com/show_bug.cgi?id=2213639https://access.redhat.com/errata/RHSA-2023:5484https://access.redhat.com/errata/RHSA-2023:5485https://access.redhat.com/errata/RHSA-2023:5486https://access.redhat.com/errata/RHSA-2023:5488https://access.redhat.com/security/cve/CVE-2023-3171https://bugzilla.redhat.com/show_bug.cgi?id=2213639
2023-12-27
Published