An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated pauses. We recommend upgrading libraries beyond the vulnerable versions.
2022-01-10T14:10:16.747
2024-11-21T05:50:20.647
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:M/Au:N/C:N/I:N/A:P
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | google-protobuf | < 3.19.2 | Yes | |
Application | protobuf-java | < 3.16.1 | Yes | |
Application | protobuf-java | < 3.18.2 | Yes | |
Application | protobuf-java | < 3.19.2 | Yes | |
Application | protobuf-kotlin | < 3.18.2 | Yes | |
Application | protobuf-kotlin | < 3.19.2 | Yes | |
Application | oracle | communications_cloud_native_core_console | 1.9.0 | Yes |
Application | oracle | communications_cloud_native_core_network_repository_function | 1.15.0 | Yes |
Application | oracle | communications_cloud_native_core_network_repository_function | 1.15.1 | Yes |
Application | oracle | communications_cloud_native_core_policy | 1.15.0 | Yes |
Application | oracle | spatial_and_graph_mapviewer | 19c | Yes |
Application | oracle | spatial_and_graph_mapviewer | 21c | Yes |