← All CVEs

CVE-2011-5034

high · 7.8

Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters. NOTE: this might overlap CVE-2011-4461.

7.8
CVSS
80.6%
EPSS (exploit prob.)
100th
EPSS percentile
2011-12-30
Published

AV:N/AC:L/Au:N/C:N/I:N/A:C

Weaknesses

CWE-20

Affected products

VendorProductAffected versions
apachegeronimo<= 2.2.1
apachegeronimo1.0
apachegeronimo1.1
apachegeronimo1.1.1
apachegeronimo1.2
apachegeronimo2.0.1
apachegeronimo2.0.2
apachegeronimo2.1
apachegeronimo2.1.1
apachegeronimo2.1.2
apachegeronimo2.1.3
apachegeronimo2.1.4
apachegeronimo2.1.5
apachegeronimo2.1.6
apachegeronimo2.1.7
apachegeronimo2.1.8
apachegeronimo2.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2011-5034