CVE-2022-23913: Apache ActiveMQ Artemis DoS
In Apache ActiveMQ Artemis prior to 2.20.0 or 2.19.1, an attacker could partially disrupt availability (DoS) through uncontrolled resource consumption of memory.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.apache.activemq:artemis-core-clientto a version that resolves this vulnerability.Fixed in 2.19.1 - Upgrade
Upgrade
redhat/eap7-activemq-artemisto a version that resolves this vulnerability.Fixed in 0:2.16.0-9.redhat_00042.1.el8ea - Upgrade
Upgrade
redhat/eap7-activemq-artemisto a version that resolves this vulnerability.Fixed in 0:2.16.0-9.redhat_00042.1.el7ea - Upgrade
Upgrade
redhat/rh-sso7-keycloakto a version that resolves this vulnerability.Fixed in 0:18.0.3-1.redhat_00001.1.el7 - Upgrade
Upgrade
redhat/rh-sso7-keycloakto a version that resolves this vulnerability.Fixed in 0:18.0.3-1.redhat_00001.1.el8 - Upgrade
Upgrade
redhat/rh-sso7to a version that resolves this vulnerability.Fixed in 0:1-5.el9 - Upgrade
Upgrade
redhat/rh-sso7-javapackages-toolsto a version that resolves this vulnerability.Fixed in 0:6.0.0-7.el9 - Upgrade
Upgrade
redhat/rh-sso7-keycloakto a version that resolves this vulnerability.Fixed in 0:18.0.3-1.redhat_00001.1.el9 - Upgrade
Upgrade
redhat/artemisto a version that resolves this vulnerability.Fixed in 2.19.1 - Upgrade
Upgrade
redhat/artemisto a version that resolves this vulnerability.Fixed in 2.20.0
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-23913?
CVE-2022-23913 is a vulnerability in Apache ActiveMQ Artemis that allows an attacker to partially disrupt availability through uncontrolled resource consumption.
What is the severity of CVE-2022-23913?
CVE-2022-23913 has a severity rating of 7.5 (high).
Which versions of Apache ActiveMQ Artemis are affected by CVE-2022-23913?
CVE-2022-23913 affects Apache ActiveMQ Artemis prior to version 2.20.0 or 2.19.1.
How can an attacker exploit CVE-2022-23913?
An attacker can exploit CVE-2022-23913 by consuming excessive resources, leading to a denial-of-service (DoS) situation.
Are there any remediation steps available for CVE-2022-23913?
Yes, the recommended remedy versions for CVE-2022-23913 are 2.19.1 or 2.20.0 for Apache ActiveMQ Artemis.