Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2022-3509— Parsing issue in protobuf textformat

CVSS 7.5 · High EPSS 0.14% · P33
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2022-3509

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Parsing issue in protobuf textformat
Source: NVD (National Vulnerability Database)
Vulnerability Description
A parsing issue similar to CVE-2022-3171, but with textformat in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
IBM WebSphere Application Server Liberty 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
IBM WebSphere Application Server Liberty是美国国际商业机器(IBM)公司的一款构建于Open Liberty项目之上的Java应用程序服务器。 IBM WebSphere Application Server Liberty 21.0.0.2至22.0.0.12版本存在安全漏洞,该漏洞源于文本格式数据的解析程序存在缺陷,protobuf-java core和lite容易受到拒绝服务的攻击,通过发送具有重复或未知字段的非重复嵌入消息,经过身份验证的远程攻击者可以导致长
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
GoogleProtocolBuffers 3.21.0 ~ 3.21.7 -

II. Public POCs for CVE-2022-3509

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-3509

登录查看更多情报信息。

Same Patch Batch · Google · 2022-11-01 · 31 CVEs total

CVE-2022-3370Google Chrome 资源管理错误漏洞
CVE-2022-3723Google Chrome 安全漏洞
CVE-2022-3661Google Chrome 输入验证错误漏洞
CVE-2022-3660Google Chrome 安全漏洞
CVE-2022-3659Google Chrome 资源管理错误漏洞
CVE-2022-3658Google Chrome 资源管理错误漏洞
CVE-2022-3657Google Chrome 资源管理错误漏洞
CVE-2022-3656Google Chrome 输入验证错误漏洞
CVE-2022-3655Google Chrome 缓冲区错误漏洞
CVE-2022-3654Google Chrome 资源管理错误漏洞
CVE-2022-3653Google Chrome 缓冲区错误漏洞
CVE-2022-3652Google Chrome 安全漏洞
CVE-2022-3444Google Chrome 输入验证错误漏洞
CVE-2022-3443Google Chrome 安全漏洞
CVE-2022-3373Google Chrome 缓冲区错误漏洞
CVE-2022-3304Google Chrome 安全漏洞
CVE-2022-3318Google Chrome 资源管理错误漏洞
CVE-2022-3317Google Chrome 安全漏洞
CVE-2022-3316Google Chrome 安全漏洞
CVE-2022-3315Google Chrome 安全漏洞

Showing top 20 of 31 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2022-3509

No comments yet


Leave a comment