Denial of Service Vulnerability in Apache Qpid Broker-J Affecting AMQP Protocols
CVE-2018-1298
5.9MEDIUM
Summary
A vulnerability exists in Apache Qpid Broker-J 7.0.0 that allows unauthenticated attackers to crash the broker instance via the authentication process of AMQP connections using specific SASL mechanisms. The issue arises when PLAIN or XOAUTH2 authentication is enabled, potentially compromising the availability of the service. Connections utilizing AMQP versions 0-8, 0-9, 0-91, and 0-10 could be affected, while AMQP 1.0 and HTTP connections remain secure. The broker's authentication relies on various Authentication Providers that support these mechanisms, heightening the risk if configurations are improperly managed.
Affected Version(s)
Apache Qpid Broker-J 7.0.0
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved