CVE-2016-3094
MEDIUM5.9EPSS 0.98%Improper Input Validation in org.apache.qpid:qpid-broker
Published: 10/16/2018Modified: 2/16/2024
Description
PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a denial of service (broker termination) via a crafted authentication attempt, which triggers an uncaught exception.
Affected packages (1)
- Maven/org.apache.qpid:qpid-brokerfrom 0, < 6.0.3
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.9 | CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
References (9)
- ADVISORYhttps://github.com/advisories/GHSA-jj9h-mwhq-8vhm
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2016-3094
- WEBhttp://mail-archives.apache.org/mod_mbox/qpid-users/201605.mbox/%3C5748641A.2050701%40gmail.com%3E
- WEBhttp://packetstormsecurity.com/files/137215/Apache-Qpid-Java-Broker-6.0.2-Denial-Of-Service.html
- WEBhttp://qpid.apache.org/releases/qpid-java-6.0.3/release-notes.html
- WEBhttps://issues.apache.org/jira/browse/QPID-7271
- WEBhttps://svn.apache.org/viewvc?view=revision&revision=1744403
- WEBhttp://www.securityfocus.com/archive/1/538507/100/0/threaded
- WEBhttp://www.securitytracker.com/id/1035982