Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exceeding the stack limit i.e. StackOverflow. Parsing nested groups as unknown fields with DiscardUnknownFieldsParser or Java Protobuf Lite parser, or against Protobuf map fields, creates unbounded recursions that can be abused by an attacker.
Metrics
Affected Vendors & Products
References
History
Thu, 14 Nov 2024 02:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Redhat amq Streams
|
|
CPEs | cpe:/a:redhat:amq_streams:2 | |
Vendors & Products |
Redhat amq Streams
|
Fri, 11 Oct 2024 02:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Redhat
Redhat camel Quarkus |
|
CPEs | cpe:/a:redhat:camel_quarkus:3.8 | |
Vendors & Products |
Redhat
Redhat camel Quarkus |
Thu, 19 Sep 2024 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Google
Google google-protobuf Google protobuf Google protobuf-java Google protobuf-javalite Google protobuf-kotlin Google protobuf-kotlin-lite |
|
CPEs | cpe:2.3:a:google:google-protobuf:*:*:*:*:*:ruby:*:* cpe:2.3:a:google:protobuf-java:*:*:*:*:*:*:*:* cpe:2.3:a:google:protobuf-javalite:*:*:*:*:*:*:*:* cpe:2.3:a:google:protobuf-kotlin-lite:*:*:*:*:*:*:*:* cpe:2.3:a:google:protobuf-kotlin:*:*:*:*:*:*:*:* cpe:2.3:a:google:protobuf:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Google
Google google-protobuf Google protobuf Google protobuf-java Google protobuf-javalite Google protobuf-kotlin Google protobuf-kotlin-lite |
|
Metrics |
ssvc
|
Thu, 19 Sep 2024 09:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|
Thu, 19 Sep 2024 00:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exceeding the stack limit i.e. StackOverflow. Parsing nested groups as unknown fields with DiscardUnknownFieldsParser or Java Protobuf Lite parser, or against Protobuf map fields, creates unbounded recursions that can be abused by an attacker. | |
Title | Stack overflow in Protocol Buffers Java Lite | |
Weaknesses | CWE-20 | |
References |
| |
Metrics |
cvssV4_0
|
MITRE
Status: PUBLISHED
Assigner: Google
Published: 2024-09-19T00:18:45.824Z
Updated: 2024-09-19T14:46:14.517Z
Reserved: 2024-07-29T21:41:56.116Z
Link: CVE-2024-7254
Vulnrichment
Updated: 2024-09-19T14:45:43.287Z
NVD
Status : Awaiting Analysis
Published: 2024-09-19T01:15:10.963
Modified: 2024-09-20T12:30:17.483
Link: CVE-2024-7254
Redhat