Description

Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exceeding the stack limit i.e. StackOverflow. Parsing nested groups as unknown fields with DiscardUnknownFieldsParser or Java Protobuf Lite parser, or against Protobuf map fields, creates unbounded recursions that can be abused by an attacker.

INFO

Published Date :

2024-09-19T00:18:45.824Z

Last Modified :

2025-09-08T09:37:53.702Z

Source :

Google
AFFECTED PRODUCTS

The following products are affected by CVE-2024-7254 vulnerability.

Vendors Products
Google
  • Google-protobuf
  • Protobuf
  • Protobuf-java
  • Protobuf-javalite
  • Protobuf-kotlin
  • Protobuf-kotlin-lite
Netapp
  • Active Iq Unified Manager
  • Bluexp
  • Ontap Tools
Redhat
  • Amq Streams
  • Apache Camel Spring Boot
  • Camel Quarkus
  • Jboss Enterprise Application Platform
  • Quarkus
  • Trusted Profile Analyzer

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact