7.5

CVE-2024-7254

Stack overflow in Protocol Buffers Java Lite

Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exceeding the stack limit i.e. StackOverflow. Parsing nested groups as unknown fields with DiscardUnknownFieldsParser or Java Protobuf Lite parser, or against Protobuf map fields, creates unbounded recursions that can be abused by an attacker.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Google ≫ Protobuf SwPlatform ruby Version < 3.25.5
Google ≫ Protobuf SwPlatform ruby Version >= 4.0.0 < 4.27.5
Google ≫ Protobuf SwPlatform ruby Version >= 4.28.0 < 4.28.2
Google ≫ Protobuf-java Version < 3.25.5
Google ≫ Protobuf-java Version >= 4.0.0 < 4.27.5
Google ≫ Protobuf-java Version >= 4.28.0 < 4.28.2
Google ≫ Protobuf-javalite Version < 3.25.5
Google ≫ Protobuf-javalite Version >= 4.0.0 < 4.27.5
Google ≫ Protobuf-javalite Version >= 4.28.0 < 4.28.2
Google ≫ Protobuf-kotlin Version < 3.25.5
Google ≫ Protobuf-kotlin Version >= 4.0.0 < 4.27.5
Google ≫ Protobuf-kotlin Version >= 4.28.0 < 4.28.2
Google ≫ Protobuf-kotlin-lite Version < 3.25.5
Google ≫ Protobuf-kotlin-lite Version >= 4.0.0 < 4.27.5
Google ≫ Protobuf-kotlin-lite Version >= 4.28.0 <= 4.28.2
Netapp ≫ Active Iq Unified Manager Version - SwPlatform linux
Netapp ≫ Active Iq Unified Manager Version - SwPlatform vmware_vsphere
Netapp ≫ Active Iq Unified Manager Version - SwPlatform windows
Netapp ≫ Bluexp Version -
Netapp ≫ Ontap Tools Version 10 SwPlatform vmware_vsphere
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.77% 0.845
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
cve-coordination@google.com 8.7 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource.

CWE-674 Uncontrolled Recursion

The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://github.com/protocolbuffers/protobuf/commit/cc8b3483a5584b3301e3d43d17eb59704857ffaa
Patch
https://security.netapp.com/advisory/ntap-20241213-0010/
Third Party Advisory
https://security.netapp.com/advisory/ntap-20250418-0006/
Third Party Advisory