CVE-2021-4040
Broker: Malformed message can result in partial DoS (OOM)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A flaw was found in AMQ Broker. This issue can cause a partial interruption to the availability of AMQ Broker via an Out of memory (OOM) condition. This flaw allows an attacker to partially disrupt availability to the broker through a sustained attack of maliciously crafted messages. The highest threat from this vulnerability is system availability.
Se ha encontrado un fallo en AMQ Broker. Este problema puede causar una interrupción parcial de la disponibilidad de AMQ Broker por medio de una condición de Out of memory (OOM). Este fallo permite a un atacante interrumpir parcialmente la disponibilidad del broker mediante un ataque sostenido de mensajes maliciosamente diseñados. La mayor amenaza de esta vulnerabilidad es la disponibilidad del sistema.
AMQ Broker is a high-performance messaging implementation based on ActiveMQ Artemis. It uses an asynchronous journal for fast message persistence, and supports multiple languages, protocols, and platforms. This release of Red Hat AMQ Broker 7.10.0 serves as a replacement for Red Hat AMQ Broker 7.9.4, and includes security and bug fixes, and enhancements. For further information, refer to the release notes linked to in the References section. Issues addressed include HTTP request smuggling and denial of service vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-12-02 CVE Reserved
- 2022-06-20 CVE Published
- 2024-08-03 CVE Updated
- 2025-06-20 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-400: Uncontrolled Resource Consumption
- CWE-787: Out-of-bounds Write
CAPEC
References (4)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/apache/activemq-artemis/pull/3871/commits | 2022-08-29 | |
https://issues.apache.org/jira/browse/ARTEMIS-3593 | 2022-08-29 |
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2021-4040 | 2022-06-16 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2028254 | 2022-06-16 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Redhat Search vendor "Redhat" | Amq Broker Search vendor "Redhat" for product "Amq Broker" | < 7.10.0 Search vendor "Redhat" for product "Amq Broker" and version " < 7.10.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Activemq Artemis Search vendor "Apache" for product "Activemq Artemis" | < 2.19.1 Search vendor "Apache" for product "Activemq Artemis" and version " < 2.19.1" | - |
Affected
|