Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-25897


The package org.eclipse.milo:sdk-server before 0.6.8 are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory consumption by sending multiple CloseSession requests with the deleteSubscription parameter equal to False.


Published

2022-09-08T05:15:07.410

Last Modified

2024-11-21T06:53:11.030

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.9 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-770

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application eclipse milo < 0.6.8 Yes

References