An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated pauses. We recommend upgrading libraries beyond the vulnerable versions.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HGoogle Protobuf
APPGoogle< 3.19.2Google Protobuf Java
APPGoogle< 3.16.13.18.0 – 3.18.2 (bez)3.19.0 – 3.19.2 (bez)Google Protobuf Kotlin
APPGoogle< 3.18.23.19.0 – 3.19.2 (bez)Oracle Communications Cloud Native Core Console
APPOracle1.9.0Oracle Communications Cloud Native Core Network Repository Function
APPOracle1.15.01.15.1Oracle Communications Cloud Native Core Policy
APPOracle1.15.0Oracle Spatial And Graph Mapviewer
APPOracle19c21c
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Referencje
Powiązane podatności
CVE-2022-22965CRITICAL9.8⚠ KEVPL ✓ten sam produkt
Spring4Shell — RCE przez data binding w Spring MVC/WebFlux na JDK 9+
CVE-2022-22963CRITICAL9.8⚠ KEVPL ✓ten sam produkt
RCE w Spring Cloud Function poprzez złośliwy SpEL routing-expression
CVE-2022-22947CRITICAL10.0⚠ KEVPL ✓ten sam produkt
RCE poprzez code injection w VMware Spring Cloud Gateway (Actuator endpoint)
CVE-2021-3773CRITICAL9.8PL ✓ten sam produkt
Wyciek informacji o endpointach OpenVPN przez błąd w netfilter (Linux Kernel)
CVE-2022-23221CRITICAL9.8PL ✓ten sam produkt
RCE w H2 Console poprzez złośliwy JDBC URL (INIT=RUNSCRIPT)