CVE-2011-5034
Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters. NOTE: this might overlap CVE-2011-4461.
- Affected products
- Apache Geronimo
- Apache Geronimo
- ≤ 2.2.1, 1.0, 1.1, 1.1.1, 1.2, 2.0.1, 2.0.2, 2.1, 2.1.1, 2.1.2, 2.1.3, 2.1.4, 2.1.5, 2.1.6, 2.1.7, 2.1.8, 2.2
- CVSS 2.0
- 7.8 HIGH
- EPSS
- 81.2% (100th percentile)
- Weakness
- CWE-20
- NVD status
- Modified
- Published
- 2011-12-30
CVE-2011-5034 at NVD
6 known exploits for CVE-2011-5034
Proof-of-concept code and exploit modules indexed by Sploitus