An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated pauses. We recommend upgrading libraries beyond the vulnerable versions.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HGoogle Protobuf
APPGoogle< 3.19.2Google Protobuf Java
APPGoogle< 3.16.13.18.0 – 3.18.2 (excl.)3.19.0 – 3.19.2 (excl.)Google Protobuf Kotlin
APPGoogle< 3.18.23.19.0 – 3.19.2 (excl.)Oracle Communications Cloud Native Core Console
APPOracle1.9.0Oracle Communications Cloud Native Core Network Repository Function
APPOracle1.15.01.15.1Oracle Communications Cloud Native Core Policy
APPOracle1.15.0Oracle Spatial And Graph Mapviewer
APPOracle19c21c
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
References
Related vulnerabilities
CVE-2022-22965CRITICAL9.8⚠ KEVPL ✓same product
Spring4Shell — RCE przez data binding w Spring MVC/WebFlux na JDK 9+
CVE-2022-22963CRITICAL9.8⚠ KEVPL ✓same product
RCE w Spring Cloud Function poprzez złośliwy SpEL routing-expression
CVE-2022-22947CRITICAL10.0⚠ KEVPL ✓same product
RCE poprzez code injection w VMware Spring Cloud Gateway (Actuator endpoint)
CVE-2021-3773CRITICAL9.8PL ✓same product
Wyciek informacji o endpointach OpenVPN przez błąd w netfilter (Linux Kernel)
CVE-2022-23221CRITICAL9.8PL ✓same product
RCE w H2 Console poprzez złośliwy JDBC URL (INIT=RUNSCRIPT)