CVE-2022-25897: Denial of Service (DoS)
A flaw was found in the Eclipse Milo SDK Server. This flaw allows an attacker to consume the application memory, leading to a denial of service by sending specific requests.
Other sources
The package org.eclipse.milo:sdk-server before 0.6.8 are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory consumption by sending multiple CloseSession requests with the deleteSubscription parameter equal to False.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-25897?
CVE-2022-25897 is a vulnerability in the Eclipse Milo SDK Server that allows an attacker to cause a Denial of Service by sending multiple CloseSession requests.
How severe is CVE-2022-25897?
CVE-2022-25897 has a severity rating of 7.5 (high).
What is the affected software?
The affected software is the org.eclipse.milo:sdk-server package before version 0.6.8.
What is the fix for CVE-2022-25897?
To fix CVE-2022-25897, update the affected org.eclipse.milo:sdk-server package to version 0.6.8 or higher.
What is the Common Weakness Enumeration (CWE) for CVE-2022-25897?
The CWE for CVE-2022-25897 is CWE-770 (Use of One-way Hash without a Salt).