CVE-2023-46120

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-46120
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-46120.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-46120
Aliases
Related
Published
2023-10-25T18:17:36Z
Modified
2024-10-22T05:28:46.862360Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. maxBodyLebgth was not used when receiving Message objects. Attackers could send a very large Message causing a memory overflow and triggering an OOM Error. Users of RabbitMQ may suffer from DoS attacks from RabbitMQ Java client which will ultimately exhaust the memory of the consumer. This vulnerability was patched in version 5.18.0.

References

Affected packages

Git / github.com/rabbitmq/rabbitmq-java-client

Affected ranges

Type
GIT
Repo
https://github.com/rabbitmq/rabbitmq-java-client
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

Other

rabbitmq_v1_4_0
rabbitmq_v1_5_0
rabbitmq_v1_5_1
rabbitmq_v1_5_2
rabbitmq_v1_5_3
rabbitmq_v1_5_4
rabbitmq_v1_5_5
rabbitmq_v1_6_0
rabbitmq_v1_7_0
rabbitmq_v1_7_1
rabbitmq_v1_7_2
rabbitmq_v1_8_0
rabbitmq_v1_8_1
rabbitmq_v2_0_0
rabbitmq_v2_1_0
rabbitmq_v2_1_1
rabbitmq_v2_2_0
rabbitmq_v2_3_0
rabbitmq_v2_3_1
rabbitmq_v2_4_0
rabbitmq_v2_4_1
rabbitmq_v2_5_0
rabbitmq_v2_6_0
rabbitmq_v2_6_1
rabbitmq_v2_7_0
rabbitmq_v2_7_1
rabbitmq_v2_8_0
rabbitmq_v2_8_1
rabbitmq_v2_8_2
rabbitmq_v3_0_0
rabbitmq_v3_0_1
rabbitmq_v3_0_2
rabbitmq_v3_0_3
rabbitmq_v3_0_4
rabbitmq_v3_1_0
rabbitmq_v3_1_1
rabbitmq_v3_1_2
rabbitmq_v3_1_3
rabbitmq_v3_1_4
rabbitmq_v3_1_5
rabbitmq_v3_2_0
rabbitmq_v3_2_1
rabbitmq_v3_2_2
rabbitmq_v3_2_3
rabbitmq_v3_2_4
rabbitmq_v3_3_0
rabbitmq_v3_3_1
rabbitmq_v3_3_2
rabbitmq_v3_3_3
rabbitmq_v3_3_4
rabbitmq_v3_3_5
rabbitmq_v3_4_0
rabbitmq_v3_4_1
rabbitmq_v3_4_2
rabbitmq_v3_4_3
rabbitmq_v3_4_4
rabbitmq_v3_5_0
rabbitmq_v3_5_1
rabbitmq_v3_5_2
rabbitmq_v3_5_3
rabbitmq_v3_5_4
rabbitmq_v3_5_5
rabbitmq_v3_5_6
rabbitmq_v3_5_7
rabbitmq_v3_5_7_rc1
rabbitmq_v3_5_7_rc2
rabbitmq_v3_5_8
rabbitmq_v3_6_0
rabbitmq_v3_6_0_milestone1
rabbitmq_v3_6_0_milestone2
rabbitmq_v3_6_0_milestone3
rabbitmq_v3_6_0_rc1
rabbitmq_v3_6_0_rc2
rabbitmq_v3_6_0_rc3
rabbitmq_v3_6_1
rabbitmq_v3_6_10
rabbitmq_v3_6_10_milestone1
rabbitmq_v3_6_10_milestone2
rabbitmq_v3_6_10_milestone3
rabbitmq_v3_6_10_milestone4
rabbitmq_v3_6_10_rc1
rabbitmq_v3_6_10_rc2
rabbitmq_v3_6_11_milestone1
rabbitmq_v3_6_11_milestone2
rabbitmq_v3_6_11_milestone3
rabbitmq_v3_6_1_rc1
rabbitmq_v3_6_1_rc2
rabbitmq_v3_6_2
rabbitmq_v3_6_2_milestone1
rabbitmq_v3_6_2_milestone2
rabbitmq_v3_6_2_milestone3
rabbitmq_v3_6_2_milestone4
rabbitmq_v3_6_2_milestone5
rabbitmq_v3_6_2_rc1
rabbitmq_v3_6_2_rc2
rabbitmq_v3_6_2_rc3
rabbitmq_v3_6_2_rc4
rabbitmq_v3_6_3
rabbitmq_v3_6_3_milestone1
rabbitmq_v3_6_3_milestone2
rabbitmq_v3_6_3_rc1
rabbitmq_v3_6_3_rc2
rabbitmq_v3_6_3_rc3
rabbitmq_v3_6_4
rabbitmq_v3_6_4_milestone1
rabbitmq_v3_6_4_milestone2
rabbitmq_v3_6_4_rc1
rabbitmq_v3_6_5
rabbitmq_v3_6_5_milestone1
rabbitmq_v3_6_5_milestone2
rabbitmq_v3_6_6
rabbitmq_v3_6_6_milestone1
rabbitmq_v3_6_6_milestone2
rabbitmq_v3_6_6_milestone3
rabbitmq_v3_6_6_milestone4
rabbitmq_v3_6_6_milestone5
rabbitmq_v3_6_6_rc1
rabbitmq_v3_6_6_rc2
rabbitmq_v3_6_7
rabbitmq_v3_6_7_milestone1
rabbitmq_v3_6_7_milestone2
rabbitmq_v3_6_7_milestone3
rabbitmq_v3_6_7_milestone4
rabbitmq_v3_6_7_milestone5
rabbitmq_v3_6_7_milestone6
rabbitmq_v3_6_7_rc1
rabbitmq_v3_6_7_rc2
rabbitmq_v3_6_7_rc3
rabbitmq_v3_6_8
rabbitmq_v3_6_9
rabbitmq_v3_7_0_milestone1
rabbitmq_v3_7_0_milestone10
rabbitmq_v3_7_0_milestone11
rabbitmq_v3_7_0_milestone12
rabbitmq_v3_7_0_milestone13
rabbitmq_v3_7_0_milestone14
rabbitmq_v3_7_0_milestone15
rabbitmq_v3_7_0_milestone2
rabbitmq_v3_7_0_milestone3
rabbitmq_v3_7_0_milestone4
rabbitmq_v3_7_0_milestone5
rabbitmq_v3_7_0_milestone6
rabbitmq_v3_7_0_milestone7
rabbitmq_v3_7_0_milestone8
rabbitmq_v3_7_0_milestone9
try-rabbitmq-java-client-293
try-rabbitmq-java-client-294

rabbitmq_v2.*

rabbitmq_v2.6.0

v4.*

v4.0.0
v4.0.0.M1
v4.0.0.M2
v4.0.0.RC1
v4.0.0.RC2
v4.0.1
v4.0.2
v4.0.2.RC1
v4.0.3
v4.0.3.RC1
v4.0.3.RC2
v4.1.0
v4.1.0.RC1
v4.1.1
v4.1.1.RC1
v4.1.1.RC2
v4.1.1.RC3
v4.1.1.ci.preview
v4.2.0
v4.2.0.RC1
v4.2.1
v4.2.1.RC1
v4.2.2
v4.3.0
v4.3.0.RC1
v4.3.0.RC2
v4.4.0
v4.4.0.RC1
v4.4.0.RC2
v4.4.1
v4.4.2
v4.4.2.RC1
v4.4.2.RC2
v4.5.0
v4.5.0.RC1
v4.5.0.RC2
v4.5.0.RC3
v4.6.0
v4.6.0.RC1
v4.7.0
v4.7.0.RC1

v5.*

v5.0.0
v5.0.0.RC1
v5.1.0
v5.1.0.RC1
v5.1.1
v5.1.2
v5.1.2.RC1
v5.1.2.RC2
v5.10.0
v5.10.0.RC1
v5.10.0.RC2
v5.11.0
v5.11.0.RC1
v5.12.0
v5.12.0.RC1
v5.13.0
v5.13.0.RC1
v5.13.0.RC2
v5.14.0
v5.14.0.RC1
v5.15.0
v5.15.0.RC1
v5.16.0
v5.16.0.RC1
v5.17.0
v5.17.0.RC1
v5.17.0.RC2
v5.2.0
v5.2.0.RC1
v5.3.0
v5.3.0.RC1
v5.4.0
v5.4.0.M1
v5.4.0.RC1
v5.4.0.RC2
v5.4.0.RC3
v5.5.0
v5.5.0.RC1
v5.6.0
v5.6.0.RC1
v5.7.0
v5.7.0.RC1
v5.8.0
v5.8.0.RC1
v5.8.0.RC2
v5.9.0
v5.9.0.RC1

v6.*

v6.0.0.M1