[MAVEN:GHSA-X337-43MR-GG3H] Ignite Realtime Openfire allows remote authenticated users to cause a denial of service

Severity Moderate
Affected Packages 2
Fixed Packages 2
CVEs 1

ConnectionManagerImpl.java in Ignite Realtime Openfire 3.4.5 allows remote authenticated users to cause a denial of service (daemon outage) by triggering large outgoing queues without reading messages.

ID
MAVEN:GHSA-X337-43MR-GG3H
Severity
moderate
URL
https://github.com/advisories/GHSA-x337-43mr-gg3h
Published
2022-05-01T23:42:48
(2 years ago)
Modified
2024-02-16T17:36:29
(7 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.igniterealtime.openfire/parent org.igniterealtime.openfire parent < 3.5.0
Fixed pkg:maven/org.igniterealtime.openfire/parent org.igniterealtime.openfire parent = 3.5.0
Affected pkg:maven/org.igniterealtime.openfire/openfire org.igniterealtime.openfire openfire < 3.5.0
Fixed pkg:maven/org.igniterealtime.openfire/openfire org.igniterealtime.openfire openfire = 3.5.0
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...