What the vulnerability does

01Description

It was found that when Artemis and HornetQ before 2.4.0 are configured with UDP discovery and JGroups discovery a huge byte array is created when receiving an unexpected multicast message. This may result in a heap memory exhaustion, full GC, or OutOfMemoryError.

Key dates

02Disclosure timeline

March 7, 2018 CVE published
August 5, 2024 Record updated