漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Vert.x STOMP server process client frames that would not send initially a connect frame
Vulnerability Description
Vert.x STOMP is a vert.x implementation of the STOMP specification that provides a STOMP server and client. From versions 3.1.0 until 3.9.16 and 4.0.0 until 4.4.2, a Vert.x STOMP server processes client STOMP frames without checking that the client send an initial CONNECT frame replied with a successful CONNECTED frame. The client can subscribe to a destination or publish message without prior authentication. Any Vert.x STOMP server configured with an authentication handler is impacted. The issue is patched in Vert.x 3.9.16 and 4.4.2. There are no trivial workarounds.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Vulnerability Type
认证机制不恰当
Vulnerability Title
vert.x-stomp 授权问题漏洞
Vulnerability Description
vert.x-stomp是Eclipse Vert.x开源的一个 STOMP 客户端/服务器实现。 vert.x-stomp 3.1.0至3.9.16之前版本和4.0.0至4.4.2之前版本存在授权问题漏洞,该漏洞源于客户端无需事先身份验证即可订阅目的地或发布消息。
CVSS Information
N/A
Vulnerability Type
N/A