PT-2021-20058 · Emq · Emq X Broker
Jonathan Knudsen
·
Published
2021-06-08
·
Updated
2021-06-16
·
CVE-2021-33175
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
EMQ X Broker versions prior to 4.2.8
Description
The issue is related to the handling of untrusted inputs, which causes excessive memory consumption. This results in a denial of service attack, where the message broker consumes large amounts of memory, leading to the application being terminated by the operating system.
Recommendations
For EMQ X Broker versions prior to 4.2.8, update to version 4.2.8 or later to resolve the issue. As a temporary workaround, consider restricting the handling of untrusted inputs to minimize the risk of excessive memory consumption.
Fix
Deserialization of Untrusted Data
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Emq X Broker