« Volver al listado

CVE-2022-3509

Estado: ModificadaAlta (7.5)—

A parsing issue similar to CVE-2022-3171, but with textformat in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-3509",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-3509",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-22T15:09:47.292910Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve-coordination@google.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve-coordination@google.com",
      "affectedData": [
        {
          "repo": "https://github.com/protocolbuffers/protobuf/",
          "vendor": "Google",
          "product": "ProtocolBuffers",
          "versions": [
            {
              "status": "affected",
              "version": "3.21.0",
              "lessThan": "3.21.7",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "3.20.0",
              "lessThan": "3.20.3",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "3.19.0",
              "lessThan": "3.19.6",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "3.16.0",
              "lessThan": "3.16.3",
              "versionType": "semver"
            }
          ],
          "platforms": [
            "all"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2022-12-12T13:15:14.607",
  "references": [
    {
      "url": "https://github.com/protocolbuffers/protobuf/commit/a3888f53317a8018e7a439bac4abeb8f3425d5e9",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "cve-coordination@google.com"
    },
    {
      "url": "https://github.com/protocolbuffers/protobuf/commit/a3888f53317a8018e7a439bac4abeb8f3425d5e9",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-400"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A parsing issue similar to CVE-2022-3171, but with textformat in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above."
    },
    {
      "lang": "es",
      "value": "Un problema de análisis similar a CVE-2022-3171, pero con formato de texto en las versiones core y lite de protobuf-java anteriores a 3.21.7, 3.20.3, 3.19.6 y 3.16.3 puede provocar un ataque de Denegación de Servicio (DoS). Las entradas que contienen múltiples instancias de mensajes incrustados no repetidos con campos repetidos o desconocidos hacen que los objetos se conviertan de un lado a otro entre formas mutables e inmutables, lo que resulta en pausas de recolección de basura potencialmente largas. Recomendamos actualizar a las versiones mencionadas anteriormente."
    }
  ],
  "lastModified": "2026-06-17T04:59:39.570",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:google:protobuf-java:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AB303B67-87A7-43AC-8A8B-B037C2D06B3F",
              "versionEndExcluding": "3.16.3",
              "versionStartIncluding": "3.16.0"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-java:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3C2D62DC-0F66-4A30-B9FE-EA6199E60538",
              "versionEndExcluding": "3.19.6",
              "versionStartIncluding": "3.19.0"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-java:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "56CA1E8D-A555-4F4F-80D8-F23D0DC50BB8",
              "versionEndExcluding": "3.20.3",
              "versionStartIncluding": "3.20.0"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-java:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E82CFAC2-2F65-45FD-88D9-D42145FC4A4F",
              "versionEndExcluding": "3.21.7",
              "versionStartIncluding": "3.21.0"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-javalite:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "63C927E5-FAB2-4F2E-8F28-EC3CC160837C",
              "versionEndExcluding": "3.16.3",
              "versionStartIncluding": "3.16.0"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-javalite:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2B4050D4-2224-467C-B46D-2CD734B3B0FB",
              "versionEndExcluding": "3.19.6",
              "versionStartIncluding": "3.17.0"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-javalite:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "459A8615-D2ED-49F3-A81C-DC4560D96C93",
              "versionEndExcluding": "3.20.3",
              "versionStartIncluding": "3.20.0"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-javalite:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "712693B9-41AB-41D1-97B2-560FDFEE0863",
              "versionEndExcluding": "3.21.7",
              "versionStartIncluding": "3.21.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve-coordination@google.com"
}