漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
CometD has acknowledgement extension out of memory
Vulnerability Description
CometD is a scalable comet implementation for web messaging. In versions 5.0.0 through 5.0.22, 6.0.0 through 6.0.18, 7.0.0 through 7.0.18, and 8.0.0 through 8.0.8, bad clients that always send a fixed batch value when the server is using the acknowledgement extension may cause the unacknowledged message queue to grow indefinitely, eventually causing an `OutOfMemoryError`. Versions 5.0.23, 6.0.19, 7.0.19, and 8.0.9 patch the issue. As a workaround, disable the acknowledgement extension.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
未加控制的资源消耗(资源穷尽)
Vulnerability Title
cometd 资源管理错误漏洞
Vulnerability Description
CometD是CometD团队开源的一个可扩展的基于 WebSocket 和 HTTP 的事件和消息路由总线。 cometd存在资源管理错误漏洞,该漏洞源于服务器使用确认扩展时,恶意客户端始终发送固定的批次值,可能导致未确认消息队列无限增长,最终导致内存耗尽错误。以下版本受到影响:5.0.0版本至5.0.22版本、6.0.0版本至6.0.18版本、7.0.0版本至7.0.18版本和8.0.0版本至8.0.8版本。
CVSS Information
N/A
Vulnerability Type
N/A