CVE-2019-0222: Input Validation
Apache ActiveMQ is vulnerable to a denial of service, caused by improper input validation. By sending a specially-crafted MQTT frame, a remote attacker could exploit this vulnerability to cause a denial of service condition.
Other sources
In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory exception making it unresponsive.
— Ubuntu
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/activemqto a version that resolves this vulnerability.Fixed in 5.15.9 - Upgrade
Upgrade
maven/org.apache.activemq:activemq-clientto a version that resolves this vulnerability.Fixed in 5.15.9 - Upgrade
Upgrade
debian/activemqto a version that resolves this vulnerability.Fixed in 5.15.16-0+deb10u1Fixed in 5.16.1-1Fixed in 5.17.2+dfsg-2Fixed in 5.17.6+dfsg-1 - Upgrade
Upgrade
debian/mqtt-clientto a version that resolves this vulnerability.Fixed in 1.14-1+deb10u1Fixed in 1.16-1 - Upgrade
Upgrade
ubuntu/mqtt-clientto a version that resolves this vulnerability.Fixed in 1.14-1ubuntu0.18.04.1~ - Upgrade
Upgrade
ubuntu/mqtt-clientto a version that resolves this vulnerability.Fixed in 1.14-1+ - Upgrade
Upgrade
ubuntu/mqtt-clientto a version that resolves this vulnerability.Fixed in 1.10-1ubuntu0.1~
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2019-0222?
CVE-2019-0222 is a vulnerability in Apache ActiveMQ 5.0.0 - 5.15.8 that can lead to a denial of service condition.
How severe is CVE-2019-0222?
CVE-2019-0222 has a severity rating of 7.5 (High).
Which software versions are affected by CVE-2019-0222?
CVE-2019-0222 affects Apache ActiveMQ versions 5.0.0 to 5.15.8.
How can I fix CVE-2019-0222?
To fix CVE-2019-0222, upgrade to Apache ActiveMQ version 5.15.9.
Where can I find more information about CVE-2019-0222?
You can find more information about CVE-2019-0222 in the Apache ActiveMQ security advisories and the Red Hat Bugzilla report.