Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5667-3wch-7q7w

Опубликовано: 27 мар. 2024
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Eclipse Vert.x memory leak

A vulnerability in the Eclipse Vert.x toolkit results in a memory leak due to using Netty FastThreadLocal data structures. Specifically, when the Vert.x HTTP client establishes connections to different hosts, triggering the memory leak. The leak can be accelerated with intimate runtime knowledge, allowing an attacker to exploit this vulnerability. For instance, a server accepting arbitrary internet addresses could serve as an attack vector by connecting to these addresses, thereby accelerating the memory leak.

Пакеты

Наименование

io.vertx:vertx-core

maven
Затронутые версииВерсия исправления

>= 4.5.0, < 4.5.2

4.5.2

Наименование

io.vertx:vertx-core

maven
Затронутые версииВерсия исправления

>= 4.4.5, < 4.4.7

4.4.7

EPSS

Процентиль: 45%
0.00227
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-119
CWE-200

Связанные уязвимости

CVSS3: 6.5
redhat
около 2 лет назад

A vulnerability in the Eclipse Vert.x toolkit results in a memory leak due to using Netty FastThreadLocal data structures. Specifically, when the Vert.x HTTP client establishes connections to different hosts, triggering the memory leak. The leak can be accelerated with intimate runtime knowledge, allowing an attacker to exploit this vulnerability. For instance, a server accepting arbitrary internet addresses could serve as an attack vector by connecting to these addresses, thereby accelerating the memory leak.

CVSS3: 6.5
nvd
почти 2 года назад

A vulnerability in the Eclipse Vert.x toolkit results in a memory leak due to using Netty FastThreadLocal data structures. Specifically, when the Vert.x HTTP client establishes connections to different hosts, triggering the memory leak. The leak can be accelerated with intimate runtime knowledge, allowing an attacker to exploit this vulnerability. For instance, a server accepting arbitrary internet addresses could serve as an attack vector by connecting to these addresses, thereby accelerating the memory leak.

EPSS

Процентиль: 45%
0.00227
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-119
CWE-200