The package org.eclipse.milo:sdk-server before 0.6.8 are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory consumption by sending multiple CloseSession requests with the deleteSubscription parameter equal to False.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-6805 | The package org.eclipse.milo:sdk-server before 0.6.8 are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory consumption by sending multiple CloseSession requests with the deleteSubscription parameter equal to False. |
Github GHSA |
GHSA-fph9-f5r6-vhqf | Eclipse Milo vulnerable to Resource Exhaustion (Denial of Service) |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2024-09-16T17:49:20.074Z
Reserved: 2022-02-24T00:00:00
Link: CVE-2022-25897
No data.
Status : Modified
Published: 2022-09-08T05:15:07.410
Modified: 2024-11-21T06:53:11.030
Link: CVE-2022-25897
OpenCVE Enrichment
No data.
EUVD
Github GHSA