First published: Fri Nov 19 2021(Updated: )
A flaw was found in AMQ Broker. This issue can cause a partial interruption to the availability of AMQ Broker via an Out of memory (OOM) condition. This flaw allows an attacker to partially disrupt availability to the broker through a sustained attack of maliciously crafted messages. The highest threat from this vulnerability is system availability.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Amq Broker | <7.10.0 | |
Apache ActiveMQ Artemis | <2.19.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-4040 is a vulnerability found in AMQ Broker that can cause a partial interruption to the availability of the broker due to an Out of Memory (OOM) condition.
CVE-2021-4040 allows an attacker to partially disrupt the availability of AMQ Broker through a sustained attack of maliciously crafted messages.
The severity of CVE-2021-4040 is medium with a CVSS score of 5.3.
AMQ Broker version up to 7.10.0 and Apache ActiveMQ Artemis version up to 2.19.1 are affected by CVE-2021-4040.
To fix CVE-2021-4040, update your AMQ Broker to a version beyond 7.10.0 and Apache ActiveMQ Artemis to a version beyond 2.19.1.