Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9ph3-v2vh-3qx7

Опубликовано: 02 апр. 2024
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Eclipse Vert.x vulnerable to a memory leak in TCP servers

A vulnerability in the Eclipse Vert.x toolkit causes a memory leak in TCP servers configured with TLS and SNI support. When processing an unknown SNI server name assigned the default certificate instead of a mapped certificate, the SSL context is erroneously cached in the server name map, leading to memory exhaustion. This flaw allows attackers to send TLS client hello messages with fake server names, triggering a JVM out-of-memory error.

Пакеты

Наименование

io.vertx:vertx-core

maven
Затронутые версииВерсия исправления

>= 4.3.4, < 4.4.8

4.4.8

Наименование

io.vertx:vertx-core

maven
Затронутые версииВерсия исправления

>= 4.5.0, < 4.5.3

4.5.3

EPSS

Процентиль: 62%
0.01064
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-400
CWE-772

Связанные уязвимости

CVSS3: 5.4
redhat
больше 2 лет назад

A vulnerability in the Eclipse Vert.x toolkit causes a memory leak in TCP servers configured with TLS and SNI support. When processing an unknown SNI server name assigned the default certificate instead of a mapped certificate, the SSL context is erroneously cached in the server name map, leading to memory exhaustion. This flaw allows attackers to send TLS client hello messages with fake server names, triggering a JVM out-of-memory error.

CVSS3: 5.4
nvd
больше 2 лет назад

A vulnerability in the Eclipse Vert.x toolkit causes a memory leak in TCP servers configured with TLS and SNI support. When processing an unknown SNI server name assigned the default certificate instead of a mapped certificate, the SSL context is erroneously cached in the server name map, leading to memory exhaustion. This flaw allows attackers to send TLS client hello messages with fake server names, triggering a JVM out-of-memory error.

CVSS3: 5.4
fstec
больше 2 лет назад

Уязвимость набора инструментов Eclipse Vert.x, связанная с утечкой памяти, позволяющая нарушителю раскрыть защищаемую информацию или вызвать отказ в обслуживании

EPSS

Процентиль: 62%
0.01064
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-400
CWE-772