« Volver al listado

CVE-2022-3171

Estado: ModificadaAlta (7.5)—

A parsing issue with binary data in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (6)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-3171",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-3171",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-21T13:36:41.564407Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve-coordination@google.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve-coordination@google.com",
      "affectedData": [
        {
          "vendor": "Google LLC",
          "product": "Protocolbuffers",
          "versions": [
            {
              "status": "affected",
              "version": "3.21.7",
              "lessThan": "3.21.7",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "3.20.3",
              "lessThan": "3.20.3",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "3.19.6",
              "lessThan": "3.19.6",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "3.16.3",
              "lessThan": "3.16.3",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "core and lite"
          ]
        }
      ]
    }
  ],
  "published": "2022-10-12T23:15:09.807",
  "references": [
    {
      "url": "https://github.com/protocolbuffers/protobuf/security/advisories/GHSA-h4h5-3hr4-j3g2",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve-coordination@google.com"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CBAUKJQL6O4TIWYBENORSY5P43TVB4M3/",
      "source": "cve-coordination@google.com"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MPCGUT3T5L6C3IDWUPSUO22QDCGQKTOP/",
      "source": "cve-coordination@google.com"
    },
    {
      "url": "https://security.gentoo.org/glsa/202301-09",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve-coordination@google.com"
    },
    {
      "url": "https://github.com/protocolbuffers/protobuf/security/advisories/GHSA-h4h5-3hr4-j3g2",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CBAUKJQL6O4TIWYBENORSY5P43TVB4M3/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MPCGUT3T5L6C3IDWUPSUO22QDCGQKTOP/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.gentoo.org/glsa/202301-09",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve-coordination@google.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A parsing issue with binary data in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above."
    },
    {
      "lang": "es",
      "value": "Un problema de análisis de datos binarios en protobuf-java core y lite versiones anteriores a 3.21.7, 3.20.3, 3.19.6 y 3.16.3, puede conllevar a un ataque de denegación de servicio. Las entradas que contienen múltiples instancias de mensajes insertados no repetidos con campos repetidos o desconocidos causan que los objetos sean convertidos de ida y vuelta entre las formas mutables e inmutables, resultando en pausas de recolección de basura potencialmente largas. Es recomendado actualizar a versiones mencionadas anteriormente"
    }
  ],
  "lastModified": "2026-06-17T04:58:59.997",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:google:google-protobuf:*:*:*:*:*:ruby:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1097AC30-B07F-4759-B62E-86B7856DB9BF",
              "versionEndExcluding": "3.16.3"
            },
            {
              "criteria": "cpe:2.3:a:google:google-protobuf:*:*:*:*:*:ruby:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F9A3FACD-AB55-41D7-86E2-A49E55C901E9",
              "versionEndExcluding": "3.19.6",
              "versionStartIncluding": "3.17.0"
            },
            {
              "criteria": "cpe:2.3:a:google:google-protobuf:*:*:*:*:*:ruby:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C92E0E73-782B-4ABB-A1C9-FB762744E1E8",
              "versionEndExcluding": "3.20.3",
              "versionStartIncluding": "3.20.0"
            },
            {
              "criteria": "cpe:2.3:a:google:google-protobuf:*:*:*:*:*:ruby:*:*",
              "vulnerable": true,
              "matchCriteriaId": "83C75530-D5AE-4AD9-A548-E4AD87300982",
              "versionEndExcluding": "3.21.7",
              "versionStartIncluding": "3.21.0"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-java:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DC11741F-5A8A-4EBA-B4F8-046866813A97",
              "versionEndExcluding": "3.16.3"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-java:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E669203D-A2DE-4148-A966-81843737603C",
              "versionEndExcluding": "3.19.6",
              "versionStartIncluding": "3.17.0"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-java:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "56CA1E8D-A555-4F4F-80D8-F23D0DC50BB8",
              "versionEndExcluding": "3.20.3",
              "versionStartIncluding": "3.20.0"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-java:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E82CFAC2-2F65-45FD-88D9-D42145FC4A4F",
              "versionEndExcluding": "3.21.7",
              "versionStartIncluding": "3.21.0"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-javalite:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "50F55B55-9C50-4489-A1A7-9FD0893FB877",
              "versionEndExcluding": "3.16.3"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-javalite:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2B4050D4-2224-467C-B46D-2CD734B3B0FB",
              "versionEndExcluding": "3.19.6",
              "versionStartIncluding": "3.17.0"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-javalite:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "459A8615-D2ED-49F3-A81C-DC4560D96C93",
              "versionEndExcluding": "3.20.3",
              "versionStartIncluding": "3.20.0"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-javalite:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "712693B9-41AB-41D1-97B2-560FDFEE0863",
              "versionEndExcluding": "3.21.7",
              "versionStartIncluding": "3.21.0"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-kotlin:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "78B4C867-FA47-464D-85D1-DB46E5F035A6",
              "versionEndExcluding": "3.16.3"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-kotlin:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DCCCC941-D98E-4B60-A1E2-282EBFF92B17",
              "versionEndExcluding": "3.19.6",
              "versionStartIncluding": "3.17.0"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-kotlin:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "85E923BA-CB98-4B28-9BB5-A8D62E21D086",
              "versionEndExcluding": "3.20.3",
              "versionStartIncluding": "3.20.0"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-kotlin:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "81C71355-5BBB-4197-A5A6-EFDF750C4C90",
              "versionEndExcluding": "3.21.7",
              "versionStartIncluding": "3.21.0"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-kotlin-lite:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F758471D-1586-4A85-A567-85321F7B186F",
              "versionEndExcluding": "3.16.3"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-kotlin-lite:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DAA9ACA3-A94B-473B-9393-51C32473954F",
              "versionEndExcluding": "3.19.6",
              "versionStartIncluding": "3.17.0"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-kotlin-lite:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2EE1D9B6-30FC-4AB9-921B-A4A8F4E41387",
              "versionEndExcluding": "3.20.3",
              "versionStartIncluding": "3.20.0"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-kotlin-lite:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9839B552-5DAF-4892-B34D-69201B0258A2",
              "versionEndExcluding": "3.21.7",
              "versionStartIncluding": "3.21.0"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E30D0E6F-4AE8-4284-8716-991DFA48CC5D"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve-coordination@google.com"
}