Denial of Service in Apache Qpid Broker-J Affecting Versions 6.0.0 to 7.0.6
CVE-2019-0200
7.5HIGH
Summary
A Denial of Service vulnerability exists in Apache Qpid Broker-J from versions 6.0.0 to 7.0.6 and 7.1.0, allowing unauthenticated attackers to crash the broker instance. This is accomplished by sending specially crafted commands using AMQP protocol versions below 1.0 (specifically AMQP 0-8, 0-9, 0-91, and 0-10). Users operating these versions should upgrade to at least versions 7.0.7 or 7.1.1 to mitigate this issue and ensure the stability of their messaging services.
Affected Version(s)
Apache Qpid Broker-J Apache Qpid Broker-J 6.0.0 to 7.0.6 (inclusive), 7.1.0
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved