Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS12M2g4LXJ3NDgtaDRncs3ubQ

Apache Geronimo Hash Collisions Cause DoS

Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters. NOTE: this might overlap CVE-2011-4461.

Permalink: https://github.com/advisories/GHSA-v3h8-rw48-h4gr
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12M2g4LXJ3NDgtaDRncs3ubQ
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: almost 2 years ago
Updated: 4 months ago


Identifiers: GHSA-v3h8-rw48-h4gr, CVE-2011-5034
References: Repository: https://github.com/FireFart/HashCollision-DOS-POC
Blast Radius: 0.0

Affected Packages

maven:org.apache.geronimo:geronimo
Dependent packages: 4
Dependent repositories: 9
Downloads:
Affected Version Ranges: < 2.2.1
Fixed in: 2.2.1
All affected versions: 2.0.1, 2.0.2, 2.1.1, 2.1.2, 2.1.3, 2.1.4, 2.1.5, 2.1.6, 2.1.7, 2.1.8
All unaffected versions: 2.2.1, 3.0.0, 3.0.1