CVE-2021-4040
Broker: Malformed message can result in partial DoS (OOM)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A flaw was found in AMQ Broker. This issue can cause a partial interruption to the availability of AMQ Broker via an Out of memory (OOM) condition. This flaw allows an attacker to partially disrupt availability to the broker through a sustained attack of maliciously crafted messages. The highest threat from this vulnerability is system availability.
Se ha encontrado un fallo en AMQ Broker. Este problema puede causar una interrupción parcial de la disponibilidad de AMQ Broker por medio de una condición de Out of memory (OOM). Este fallo permite a un atacante interrumpir parcialmente la disponibilidad del broker mediante un ataque sostenido de mensajes maliciosamente diseñados. La mayor amenaza de esta vulnerabilidad es la disponibilidad del sistema.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-12-02 CVE Reserved
- 2022-06-20 CVE Published
- 2024-07-10 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-400: Uncontrolled Resource Consumption
- CWE-787: Out-of-bounds Write
CAPEC
References (4)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/apache/activemq-artemis/pull/3871/commits | 2022-08-29 | |
https://issues.apache.org/jira/browse/ARTEMIS-3593 | 2022-08-29 |
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2021-4040 | 2022-06-16 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2028254 | 2022-06-16 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Redhat Search vendor "Redhat" | Amq Broker Search vendor "Redhat" for product "Amq Broker" | < 7.10.0 Search vendor "Redhat" for product "Amq Broker" and version " < 7.10.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Activemq Artemis Search vendor "Apache" for product "Activemq Artemis" | < 2.19.1 Search vendor "Apache" for product "Activemq Artemis" and version " < 2.19.1" | - |
Affected
|