CVE-2022-3171
A parsing issue with binary data in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above.
- Affected products
- Alt Linux, Debian, Jira, Jira Service Management Server, Jira Work Management, Red Os, Suse, Protobuf-Java
- Google Google-protobuf
- < 3.16.3, 3.19.6, 3.20.3, 3.21.7
- Google Protobuf-java
- < 3.16.3, 3.19.6, 3.20.3, 3.21.7
- Google Protobuf-javalite
- < 3.16.3, 3.19.6, 3.20.3, 3.21.7
- Google Protobuf-kotlin
- < 3.16.3, 3.19.6, 3.20.3, 3.21.7
- Google Protobuf-kotlin-lite
- < 3.16.3, 3.19.6, 3.20.3, 3.21.7
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 1.1% (62th percentile)
- Weakness
- CWE-20
- NVD status
- Modified
- Published
- 2022-10-12
CVE-2022-3171 at NVD
No indexed exploits for CVE-2022-3171 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2022-3171 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.