« Volver al listado

CVE-2022-1941

Estado: ModificadaAlta (7.5)—

A parsing vulnerability for the MessageSet type in the ProtocolBuffers versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 3.21.5 for protobuf-cpp, and versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 4.21.5 for protobuf-python can lead to out of memory failures. A specially crafted message with multiple key-value per elements creates parsing issues, and can lead to a Denial of Service against services receiving unsanitized input. We recommend upgrading to versions 3.18.3, 3.19.5, 3.20.2, 3.21.6 for protobuf-cpp and 3.18.3, 3.19.5, 3.20.2, 4.21.6 for protobuf-python. Versions for 3.16 and 3.17 are no longer updated.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-1941",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-1941",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-07-16T19:20:47.222552Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve-coordination@google.com",
      "affectedData": [
        {
          "vendor": "Google LLC",
          "product": "protobuf-cpp",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "3.16.1"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "3.17.3"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "3.18.2"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "3.19.4"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "3.20.1"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "3.21.5"
            }
          ]
        },
        {
          "vendor": "Google LLC",
          "product": "protobuf-python",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "3.16.1"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "3.17.3"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "3.18.2"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "3.19.4"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "3.20.1"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "4.21.5"
            }
          ]
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:google:protobuf-cpp:*:*:*:*:*:*:*:*"
          ],
          "vendor": "google",
          "product": "protobuf-cpp",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "3.18.3",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "3.19.0",
              "lessThan": "3.19.5",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "3.20.0",
              "lessThan": "3.20.2",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "3.21.0",
              "lessThan": "3.21.6",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:google:protobuf-python:*:*:*:*:*:*:*:*"
          ],
          "vendor": "google",
          "product": "protobuf-python",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "3.18.3",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "3.19.0",
              "lessThan": "3.19.5",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "3.20.0",
              "lessThan": "3.20.2",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "4.0.0",
              "lessThan": "4.21.6",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2022-09-22T15:15:09.203",
  "references": [
    {
      "url": "http://www.openwall.com/lists/oss-security/2022/09/27/1",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "cve-coordination@google.com"
    },
    {
      "url": "https://cloud.google.com/support/bulletins#GCP-2022-019",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve-coordination@google.com"
    },
    {
      "url": "https://github.com/protocolbuffers/protobuf/security/advisories/GHSA-8gq9-2x98-w8hf",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve-coordination@google.com"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2023/04/msg00019.html",
      "tags": [
        "Mailing List"
      ],
      "source": "cve-coordination@google.com"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CBAUKJQL6O4TIWYBENORSY5P43TVB4M3/",
      "source": "cve-coordination@google.com"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MPCGUT3T5L6C3IDWUPSUO22QDCGQKTOP/",
      "source": "cve-coordination@google.com"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20240705-0001/",
      "source": "cve-coordination@google.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2022/09/27/1",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://cloud.google.com/support/bulletins#GCP-2022-019",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/protocolbuffers/protobuf/security/advisories/GHSA-8gq9-2x98-w8hf",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2023/04/msg00019.html",
      "tags": [
        "Mailing List"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CBAUKJQL6O4TIWYBENORSY5P43TVB4M3/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MPCGUT3T5L6C3IDWUPSUO22QDCGQKTOP/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20240705-0001/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve-coordination@google.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-1286"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A parsing vulnerability for the MessageSet type in the ProtocolBuffers versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 3.21.5 for protobuf-cpp, and versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 4.21.5 for protobuf-python can lead to out of memory failures. A specially crafted message with multiple key-value per elements creates parsing issues, and can lead to a Denial of Service against services receiving unsanitized input. We recommend upgrading to versions 3.18.3, 3.19.5, 3.20.2, 3.21.6 for protobuf-cpp and 3.18.3, 3.19.5, 3.20.2, 4.21.6 for protobuf-python. Versions for 3.16 and 3.17 are no longer updated."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de análisis de tipo MessageSet en ProtocolBuffers versiones anteriores a 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 y 3.21.5 para protobuf-cpp, y las versiones anteriores a la 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 y 4.21.5 para protobuf-python, entre otras, puede conllevar a fallos de memoria. Un mensaje especialmente diseñado con múltiples elementos clave-valor por crea problemas de análisis, y puede conllevar a una denegación de servicio contra los servicios que reciban entradas no saneadas. Es recomendado actualizar a versiones 3.18.3, 3.19.5, 3.20.2, 3.21.6 para protobuf-cpp y 3.18.3, 3.19.5, 3.20.2, 4.21.6 para protobuf-python. Las versiones para 3.16 y 3.17 ya no son actualizadas"
    }
  ],
  "lastModified": "2026-06-17T04:23:23.630",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:google:protobuf-cpp:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3A836785-66BB-421D-83DC-01AC558E7EB8",
              "versionEndExcluding": "3.18.3"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-cpp:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A2CE47F2-1804-4931-9DC9-A725DD3E2706",
              "versionEndExcluding": "3.19.5",
              "versionStartIncluding": "3.19.0"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-cpp:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4BA60969-22F7-4A4A-9053-EEEC7EA6F5D9",
              "versionEndExcluding": "3.20.2",
              "versionStartIncluding": "3.20.0"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-cpp:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "91BCDB1F-CBA9-4045-938F-E695AD4655B0",
              "versionEndExcluding": "3.21.6",
              "versionStartIncluding": "3.21.0"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-python:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5F35B30A-9AFA-4CFB-A28A-19ADED42D5DD",
              "versionEndExcluding": "3.18.3"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-python:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9A719BA3-DC20-4ADA-9F90-5F695609752A",
              "versionEndExcluding": "3.19.5",
              "versionStartIncluding": "3.19.0"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-python:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B6C38B17-4211-438B-A01B-6967D30DB08E",
              "versionEndExcluding": "3.20.2",
              "versionStartIncluding": "3.20.0"
            },
            {
              "criteria": "cpe:2.3:a:google:protobuf-python:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "046EB3D9-94B5-434C-A14F-6EE26F26091E",
              "versionEndExcluding": "4.21.6",
              "versionStartIncluding": "4.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5C675112-476C-4D7C-BCB9-A2FB2D0BC9FD"
            },
            {
              "criteria": "cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E30D0E6F-4AE8-4284-8716-991DFA48CC5D"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "07B237A9-69A3-4A9C-9DA0-4E06BD37AE73"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve-coordination@google.com"
}