CVE-2018-1298
CVE-2018-1298 is a medium-severity vulnerability in Apache Qpid Broker-j with a CVSS 3.x base score of 5.9. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-20.
Key facts
- Severity: Medium (CVSS 3.x base score 5.9)
- CVSS v2: 4.3
- EPSS exploit prediction: 2% (83rd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-20
- Affected product: Apache Qpid Broker-j
- Published:
- Last modified:
Description
A Denial of Service vulnerability was found in Apache Qpid Broker-J 7.0.0 in functionality for authentication of connections for AMQP protocols 0-8, 0-9, 0-91 and 0-10 when PLAIN or XOAUTH2 SASL mechanism is used. The vulnerability allows unauthenticated attacker to crash the broker instance. AMQP 1.0 and HTTP connections are not affected. An authentication of incoming AMQP connections in Apache Qpid Broker-J is performed by special entities called "Authentication Providers". Each Authentication Provider can support several SASL mechanisms which are offered to the connecting clients as part of SASL negotiation process. The client chooses the most appropriate SASL mechanism for authentication. Authentication Providers of following types supports PLAIN SASL mechanism: Plain, PlainPasswordFile, SimpleLDAP, Base64MD5PasswordFile, MD5, SCRAM-SHA-256, SCRAM-SHA-1. XOAUTH2 SASL mechanism is supported by Authentication Providers of type OAuth2. If an AMQP port is configured with any of these Authentication Providers, the Broker may be vulnerable.
Frequently asked questions
- What is CVE-2018-1298?
- A Denial of Service vulnerability was found in Apache Qpid Broker-J 7.0.0 in functionality for authentication of connections for AMQP protocols 0-8, 0-9, 0-91 and 0-10 when PLAIN or XOAUTH2 SASL mechanism is used. The vulnerability allows unauthenticated attacker to crash the broker instance. AMQP 1.0 and HTTP connections are not affected. An authentication of incoming AMQP connections in Apache Qpid Broker-J is performed by special entities called "Authentication Providers". Each Authentication Provider can support several SASL mechanisms which are offered to the connecting clients as part of SASL negotiation process. The client chooses the most appropriate SASL mechanism for authentication. Authentication Providers of following types supports PLAIN SASL mechanism: Plain, PlainPasswordFile, SimpleLDAP, Base64MD5PasswordFile, MD5, SCRAM-SHA-256, SCRAM-SHA-1. XOAUTH2 SASL mechanism is supported by Authentication Providers of type OAuth2. If an AMQP port is configured with any of these Authentication Providers, the Broker may be vulnerable.
- How severe is CVE-2018-1298?
- CVE-2018-1298 has a CVSS 3.x base score of 5.9, rated medium severity. It is exploitable over network with high attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity none, and availability high.
- Is CVE-2018-1298 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 2% (83rd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2018-1298?
- CVE-2018-1298 affects Apache Qpid Broker-j. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2018-1298?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2018-1298 published?
- CVE-2018-1298 was published on 2018-02-09 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:a:apache:qpid_broker-j:7.0.0:*:*:*:*:*:*:*
More vulnerabilities in Apache Qpid Broker-j
- CVE-2026-92609 — Critical (CVSS 9.8): Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an…
- CVE-2017-15702 — Critical (CVSS 9.8): In Apache Qpid Broker-J 0.18 through 0.32, if the broker is configured with different authentication providers on…
- CVE-2016-4432 — Critical (CVSS 9.1): The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to…
- CVE-2026-92564 — High (CVSS 7.5): A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial…
- CVE-2026-92560 — High (CVSS 7.5): A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to…
- CVE-2026-92550 — High (CVSS 7.5): A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to…
All CVEs affecting Apache Qpid Broker-j →
Other CWE-20 (Improper Input Validation) vulnerabilities
- CVE-2026-93952 — Critical (CVSS 10.0): VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access…
- CVE-2026-77554 — Critical (CVSS 10.0): A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi…
- CVE-2026-77537 — Critical (CVSS 10.0): A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi…
- CVE-2026-48056 — Critical (CVSS 10.0): Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0…
- CVE-2026-33267 — Critical (CVSS 10.0): Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0…
- CVE-2026-47668 — Critical (CVSS 10.0): DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST…
Browse all CWE-20 (Improper Input Validation) vulnerabilities →