CVE-2019-17555

HIGH

Apache Olingo 4.0.0-4.6.0 - Denial of Service via Retry-After Header

Title source: llm
STIX 2.1

Description

The AsyncResponseWrapperImpl class in Apache Olingo versions 4.0.0 to 4.6.0 reads the Retry-After header and passes it to the Thread.sleep() method without any check. If a malicious server returns a huge value in the header, then it can help to implement a DoS attack.

References (1)

Core 1

Scores

CVSS v3 7.5
EPSS 0.0220
EPSS Percentile 84.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-20
Status published
Products (2)
apache/olingo 4.0.0 - 4.6.0
org.apache.olingo/odata-client-core 4.0.0 - 4.7.0Maven
Published Dec 04, 2019
Tracked Since Feb 18, 2026