Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. io.vertx/vertx-stomp
  4. ›
  5. CVE-2023-32081

CVE-2023-32081: Improper Authentication

May 12, 2023 (updated May 24, 2023)

Vert.x STOMP is a vert.x implementation of the STOMP specification that provides a STOMP server and client. From versions 3.1.0 until 3.9.16 and 4.0.0 until 4.4.2, a Vert.x STOMP server processes client STOMP frames without checking that the client send an initial CONNECT frame replied with a successful CONNECTED frame. The client can subscribe to a destination or publish message without prior authentication. Any Vert.x STOMP server configured with an authentication handler is impacted. The issue is patched in Vert.x 3.9.16 and 4.4.2. There are no trivial workarounds.

References

  • github.com/advisories/GHSA-gvrq-cg5r-7chp
  • github.com/vert-x3/vertx-stomp/commit/0de4bc5a44ddb57e74d92c445f16456fa03f265b
  • github.com/vert-x3/vertx-stomp/security/advisories/GHSA-gvrq-cg5r-7chp
  • nvd.nist.gov/vuln/detail/CVE-2023-32081

Code Behaviors & Features

Detect and mitigate CVE-2023-32081 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 3.1.0 before 3.9.16, all versions starting from 4.0.0 before 4.4.2

Fixed versions

  • 3.9.16
  • 4.4.2

Solution

Upgrade to versions 3.9.16, 4.4.2 or above.

Impact 6.5 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-287: Improper Authentication

Source file

maven/io.vertx/vertx-stomp/CVE-2023-32081.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:14 +0000.