VYPR

Hornetq

by Red Hat

CVEs (3)

  • CVE-2017-12174HigMar 7, 2018
    risk 0.49cvss 7.5epss 0.06

    It was found that when Artemis and HornetQ before 2.4.0 are configured with UDP discovery and JGroups discovery a huge byte array is created when receiving an unexpected multicast message. This may result in a heap memory exhaustion, full GC, or OutOfMemoryError.

  • CVE-2024-51127HigNov 4, 2024
    risk 0.46cvss 7.1epss 0.01

    An issue in the createTempFile method of hornetq v2.4.9 allows attackers to arbitrarily overwrite files or access sensitive information.

  • CVE-2014-3599MedNov 12, 2019
    risk 0.35cvss 6.5epss 0.01

    HornetQ REST is vulnerable to XML External Entity due to insecure configuration of RestEasy