snowdensb / wildfly

WildFly Application Server
https://wildfly.org
GNU Lesser General Public License v2.1
0 stars 0 forks source link

artemis-core-client-2.19.0.jar: 1 vulnerabilities (highest severity is: 7.5) #136

Open mend-for-github-com[bot] opened 6 months ago

mend-for-github-com[bot] commented 6 months ago
Vulnerable Library - artemis-core-client-2.19.0.jar

Library home page: https://www.apache.org/

Path to dependency file: /messaging-activemq/subsystem/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/apache/activemq/artemis-core-client/2.19.0/artemis-core-client-2.19.0.jar,/home/wss-scanner/.m2/repository/org/apache/activemq/artemis-core-client/2.19.0/artemis-core-client-2.19.0.jar,/home/wss-scanner/.m2/repository/org/apache/activemq/artemis-core-client/2.19.0/artemis-core-client-2.19.0.jar

Vulnerabilities

CVE Severity CVSS Dependency Type Fixed in (artemis-core-client version) Remediation Possible** Reachability
CVE-2022-23913 High 7.5 artemis-core-client-2.19.0.jar Direct org.apache.activemq:artemis-core-client:2.19.1

**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation

Details

CVE-2022-23913 ### Vulnerable Library - artemis-core-client-2.19.0.jar

Library home page: https://www.apache.org/

Path to dependency file: /messaging-activemq/subsystem/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/apache/activemq/artemis-core-client/2.19.0/artemis-core-client-2.19.0.jar,/home/wss-scanner/.m2/repository/org/apache/activemq/artemis-core-client/2.19.0/artemis-core-client-2.19.0.jar,/home/wss-scanner/.m2/repository/org/apache/activemq/artemis-core-client/2.19.0/artemis-core-client-2.19.0.jar

Dependency Hierarchy: - :x: **artemis-core-client-2.19.0.jar** (Vulnerable Library)

Found in base branch: main

### Vulnerability Details

In Apache ActiveMQ Artemis prior to 2.20.0 or 2.19.1, an attacker could partially disrupt availability (DoS) through uncontrolled resource consumption of memory.

Publish Date: 2022-02-04

URL: CVE-2022-23913

### CVSS 3 Score Details (7.5)

Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: None - Integrity Impact: None - Availability Impact: High

For more information on CVSS3 Scores, click here.

### Suggested Fix

Type: Upgrade version

Origin: https://lists.apache.org/thread/fjynj57rd99s814rdn5hzvmx8lz403q2

Release Date: 2022-02-04

Fix Resolution: org.apache.activemq:artemis-core-client:2.19.1

:rescue_worker_helmet: Automatic Remediation will be attempted for this issue.

:rescue_worker_helmet:Automatic Remediation will be attempted for this issue.