The package org.eclipse.milo:sdk-server before 0.6.8 are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory consumption by sending multiple CloseSession requests with the deleteSubscription parameter equal to False.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: snyk

Published: 2022-09-08T05:05:12.190707Z

Updated: 2024-09-16T17:49:20.074Z

Reserved: 2022-02-24T00:00:00

Link: CVE-2022-25897

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-09-08T05:15:07.410

Modified: 2022-09-13T20:17:37.290

Link: CVE-2022-25897

cve-icon Redhat

Severity : Moderate

Publid Date: 2022-09-08T00:00:00Z

Links: CVE-2022-25897 - Bugzilla