Denial of Service in Apache Qpid Broker-J Affecting Versions 6.0.0 to 7.0.6
CVE-2019-0200

7.5HIGH

Key Information:

Vendor
Apache
Vendor
CVE Published:
6 March 2019

Summary

A Denial of Service vulnerability exists in Apache Qpid Broker-J from versions 6.0.0 to 7.0.6 and 7.1.0, allowing unauthenticated attackers to crash the broker instance. This is accomplished by sending specially crafted commands using AMQP protocol versions below 1.0 (specifically AMQP 0-8, 0-9, 0-91, and 0-10). Users operating these versions should upgrade to at least versions 7.0.7 or 7.1.1 to mitigate this issue and ensure the stability of their messaging services.

Affected Version(s)

Apache Qpid Broker-J Apache Qpid Broker-J 6.0.0 to 7.0.6 (inclusive), 7.1.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.