CVE-2022-25897
Denial of Service (DoS)
Severity Score
7.5
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The package org.eclipse.milo:sdk-server before 0.6.8 are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory consumption by sending multiple CloseSession requests with the deleteSubscription parameter equal to False.
El paquete org.eclipse.milo:sdk-server versiones anteriores a 0.6.8, es vulnerable a una Denegación de Servicio (DoS) al omitir las limitaciones por consumo excesivo de memoria mediante el envío de varias peticiones CloseSession con el parámetro deleteSubscription igual a False
A flaw was found in the Eclipse Milo SDK Server. This flaw allows an attacker to consume the application memory, leading to a denial of service by sending specific requests.
*Credits:
Vera Mens, Uri Katz, Sharon Brizinov of Team82 (Claroty Research)
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2022-02-24 CVE Reserved
- 2022-09-08 CVE Published
- 2024-04-29 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-770: Allocation of Resources Without Limits or Throttling
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
https://security.snyk.io/vuln/SNYK-JAVA-ORGECLIPSEMILO-2990191 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/eclipse/milo/commit/4534381760d7d9f0bf00cbf6a8449bb0d13c6ce5 | 2022-09-13 | |
https://github.com/eclipse/milo/issues/1030 | 2022-09-13 | |
https://github.com/eclipse/milo/pull/1031 | 2022-09-13 |
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2022-25897 | 2022-12-08 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2136188 | 2022-12-08 |