Allocation of Resources Without Limits or Throttling in XNIO - CVE-2022-0084

 

Allocation of Resources Without Limits or Throttling in XNIO - CVE-2022-0084

Published: May 13, 2022 / Updated: August 17, 2023


Vulnerability identifier: #VU63159
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-0084
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to notifyReadClosed method from main/java/org/xnio/StreamConnection.java logs data into debug log instead of stderr. As a result, an attacker can trigger the application to log enormous amount of data and consume all available space.


Affected software

XNIO
B2B Advanced Communications
IBM Watson Knowledge Catalog in Cloud Pak for Data
JBoss Enterprise Application Platform
Red Hat Single Sign-On
JBoss Data Grid
rh-sso7-keycloak (Red Hat package)
rh-sso7 (Red Hat package)
xnio-help
xnio
rh-sso7-javapackages-tools (Red Hat package)
openEuler
Oracle Communications Cloud Native Core Console
IBM InfoSphere Information Server

How to mitigate CVE-2022-0084

Install update from vendor's website.

B2B Advanced Communications - update to 1.0.0.12
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
JBoss Enterprise Application Platform - update to 7.4.5
Red Hat Single Sign-On - addressed in versions 7.5.3, 7.6.1
JBoss Data Grid - update to 8.3.1
rh-sso7-keycloak (Red Hat package) - addressed in versions 15.0.8-1.redhat_00001.1.el7sso, 15.0.8-1.redhat_00001.1.el8sso, 18.0.3-1.redhat_00001.1.el7sso, 18.0.3-1.redhat_00001.1.el8sso
rh-sso7 (Red Hat package) - update to 1-5.el9sso
xnio-help - update to 3.4.0-12
xnio - update to 3.4.0-12
rh-sso7-javapackages-tools (Red Hat package) - update to 6.0.0-7.el9sso
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1

External References

Related Security Bulletins