
Cloud Vulnerability DB
A community-led vulnerabilities database
In Apache ActiveMQ Artemis versions prior to 2.20.0 or 2.19.1, a vulnerability was identified that could allow attackers to partially disrupt system availability through uncontrolled memory resource consumption. The vulnerability was assigned CVE-2022-23913 and was publicly disclosed in January 2022 (CVE Mitre, Apache Advisory).
The vulnerability is classified as a Denial of Service (DoS) issue caused by uncontrolled resource consumption of memory. It received a CVSS v3.1 base score of 7.5 (HIGH) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, indicating that it can be exploited remotely with low attack complexity and requires no privileges or user interaction (NetApp Advisory).
When successfully exploited, this vulnerability could lead to a partial disruption of system availability through a Denial of Service (DoS) condition, specifically affecting memory resources of the Apache ActiveMQ Artemis system (Apache Advisory, NetApp Advisory).
The primary mitigation is to upgrade to Apache ActiveMQ Artemis version 2.20.0 or 2.19.1 (if using Java 8). No alternative workarounds have been provided by the vendor (Apache Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."