Back to Vulnerability Directory
HIGHFixed upstream

CVE-2022-23913

ActiveMQ Artemis: uncontrolled memory consumption allows partial denial of service

Technology

ActiveMQ Artemis

CVSS Score

7.5 / 10.0

Affected Versions

ActiveMQ Artemis before 2.19.1

Upstream Fix

2.19.1; 2.20.0

Published

February 4, 2022

OSSeva Coverage

Fixed upstream

Description

An attacker can partially disrupt the broker's availability through uncontrolled consumption of memory. Fixed in 2.19.1 and 2.20.0. Apache rates it high.

Upstream record: NVD · CVE.org

Is your ActiveMQ Artemis deployment affected?

If you're running ActiveMQ Artemis before 2.19.1, you need this patch. Book a discovery call to get covered.