High severity7.5NVD Advisory· Published Mar 7, 2018· Updated Jun 17, 2026
CVE-2017-12174
CVE-2017-12174
Description
It was found that when Artemis and HornetQ before 2.4.0 are configured with UDP discovery and JGroups discovery a huge byte array is created when receiving an unexpected multicast message. This may result in a heap memory exhaustion, full GC, or OutOfMemoryError.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.hornetq:hornetq-serverMaven | < 2.4.0.Final | 2.4.0.Final |
org.apache.activemq:artemis-nativeMaven | < 2.4.0 | 2.4.0 |
Affected products
3- ghsa-coords2 versions
< 2.4.0+ 1 more
- (no CPE)range: < 2.4.0
- (no CPE)range: < 2.4.0.Final
- Red Hat, Inc./HornetQ/Artemisv5Range: before 2.4.0
Patches
Vulnerability mechanics
References
16- access.redhat.com/errata/RHSA-2018:0268nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2018:0269nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2018:0270nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2018:0271nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2018:0275nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2018:0478nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2018:0479nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2018:0480nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2018:0481nvdVendor AdvisoryWEB
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor AdvisoryWEB
- github.com/advisories/GHSA-gc96-h5pr-839jghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2017-12174ghsaADVISORY
- lists.apache.org/thread.html/rb2fd3bf2dce042e0ab3f3c94c4767c96bb2e7e6737624d63162df36d%40%3Ccommits.activemq.apache.org%3EnvdWEB
- lists.apache.org/thread.html/rb2fd3bf2dce042e0ab3f3c94c4767c96bb2e7e6737624d63162df36d@%3Ccommits.activemq.apache.org%3EghsaWEB
- lists.apache.org/thread.html/rc96ad63f148f784c84ea7f0a178c84a8985c6afccabbcd9847a82088%40%3Ccommits.activemq.apache.org%3EnvdWEB
- lists.apache.org/thread.html/rc96ad63f148f784c84ea7f0a178c84a8985c6afccabbcd9847a82088@%3Ccommits.activemq.apache.org%3EghsaWEB
News mentions
0No linked articles in our index yet.