Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW12cjItOXBqNi03dzVq

Denial of Service in Google Guava

Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class (when serialized with GWT serialization) perform eager allocation without appropriate checks on what a client has sent and whether the data size is reasonable.

Permalink: https://github.com/advisories/GHSA-mvr2-9pj6-7w5j
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW12cjItOXBqNi03dzVq
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: over 4 years ago
Updated: about 1 year ago


CVSS Score: 5.9
CVSS vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Identifiers: GHSA-mvr2-9pj6-7w5j, CVE-2018-10237
References: Repository: https://github.com/google/guava
Blast Radius: 31.5

Affected Packages

maven:com.google.guava:guava
Dependent packages: 29,526
Dependent repositories: 219,576
Downloads:
Affected Version Ranges: >= 11.0, < 24.1.1-android
Fixed in: 24.1.1-android
All affected versions: 11.0.1, 11.0.2, 12.0.1, 13.0.1, 14.0.1, 16.0.1
All unaffected versions: 10.0.1
maven:org.sonatype.sisu:sisu-guava
Dependent packages: 24
Dependent repositories: 39
Downloads:
Affected Version Ranges: = 0.11.1
No known fixed version
All affected versions:
maven:org.hudsonci.lib.guava:guava
Dependent packages: 6
Dependent repositories: 1
Downloads:
Affected Version Ranges: <= 14.0.1-h-3
No known fixed version
All affected versions: 14.0.1-h-1, 14.0.1-h-3
maven:de.mhus.ports:vaadin-shared-deps
Dependent packages: 0
Dependent repositories: 0
Downloads:
Affected Version Ranges: <= 7.4.0
No known fixed version
All affected versions: 1.3.1, 1.3.4, 1.3.6, 1.3.7, 1.6.0, 1.6.1, 6.2.0, 7.0.0, 7.1.0, 7.2.0, 7.4.0
maven:com.googlecode.guava-osgi:guava-osgi
Dependent packages: 37
Dependent repositories: 50
Downloads:
Affected Version Ranges: <= 11.0.1
No known fixed version
All affected versions: 3.0.0, 4.0.0, 5.0.0, 6.0.0, 7.0.0, 8.0.0, 9.0.0, 10.0.0, 10.0.1, 11.0.0, 11.0.1
maven:com.google.guava:guava-jdk5
Dependent packages: 44
Dependent repositories: 165
Downloads:
Affected Version Ranges: <= 17.0
No known fixed version
All affected versions: 14.0.1