Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Vert.x STOMP server process client frames that would not send initially a connect frame
Vulnerability Description
Vert.x STOMP is a vert.x implementation of the STOMP specification that provides a STOMP server and client. From versions 3.1.0 until 3.9.16 and 4.0.0 until 4.4.2, a Vert.x STOMP server processes client STOMP frames without checking that the client send an initial CONNECT frame replied with a successful CONNECTED frame. The client can subscribe to a destination or publish message without prior authentication. Any Vert.x STOMP server configured with an authentication handler is impacted. The issue is patched in Vert.x 3.9.16 and 4.4.2. There are no trivial workarounds.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Vulnerability Type
认证机制不恰当
Vulnerability Title
vert.x-stomp 授权问题漏洞
Vulnerability Description
vert.x-stomp是Eclipse Vert.x开源的一个 STOMP 客户端/服务器实现。 vert.x-stomp 3.1.0至3.9.16之前版本和4.0.0至4.4.2之前版本存在授权问题漏洞,该漏洞源于客户端无需事先身份验证即可订阅目的地或发布消息。
CVSS Information
N/A
Vulnerability Type
N/A