In Eclipse Hono version 1.3.0 and 1.4.0 the AMQP protocol adapter does not verify the size of AMQP messages received from devices. In particular, a device may send messages that are bigger than the max-message-size that the protocol adapter has indicated during link establishment. While the AMQP 1.0 protocol explicitly disallows a peer to send such messages, a hand crafted AMQP 1.0 client could exploit this behavior in order to send a message of unlimited size to the adapter, eventually causing the adapter to fail with an out of memory exception.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-0938 In Eclipse Hono version 1.3.0 and 1.4.0 the AMQP protocol adapter does not verify the size of AMQP messages received from devices. In particular, a device may send messages that are bigger than the max-message-size that the protocol adapter has indicated during link establishment. While the AMQP 1.0 protocol explicitly disallows a peer to send such messages, a hand crafted AMQP 1.0 client could exploit this behavior in order to send a message of unlimited size to the adapter, eventually causing the adapter to fail with an out of memory exception.
Github GHSA Github GHSA GHSA-9f52-hpvw-v96w Improper Validation of Specified Quantity in Input in Eclipse Hono
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: eclipse

Published:

Updated: 2024-08-04T16:11:35.953Z

Reserved: 2020-10-19T00:00:00

Link: CVE-2020-27217

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-11-13T20:15:16.270

Modified: 2024-11-21T05:20:52.770

Link: CVE-2020-27217

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.