Denial of Service Vulnerability in Apache Qpid Broker-J Affecting AMQP Protocols
CVE-2018-1298
5.9MEDIUM
What is CVE-2018-1298?
A vulnerability exists in Apache Qpid Broker-J 7.0.0 that allows unauthenticated attackers to crash the broker instance via the authentication process of AMQP connections using specific SASL mechanisms. The issue arises when PLAIN or XOAUTH2 authentication is enabled, potentially compromising the availability of the service. Connections utilizing AMQP versions 0-8, 0-9, 0-91, and 0-10 could be affected, while AMQP 1.0 and HTTP connections remain secure. The broker's authentication relies on various Authentication Providers that support these mechanisms, heightening the risk if configurations are improperly managed.
Affected Version(s)
Apache Qpid Broker-J 7.0.0