Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9ph3-v2vh-3qx7

Опубликовано: 02 апр. 2024
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Eclipse Vert.x vulnerable to a memory leak in TCP servers

A vulnerability in the Eclipse Vert.x toolkit causes a memory leak in TCP servers configured with TLS and SNI support. When processing an unknown SNI server name assigned the default certificate instead of a mapped certificate, the SSL context is erroneously cached in the server name map, leading to memory exhaustion. This flaw allows attackers to send TLS client hello messages with fake server names, triggering a JVM out-of-memory error.

Пакеты

Наименование

io.vertx:vertx-core

maven
Затронутые версииВерсия исправления

>= 4.3.4, < 4.4.8

4.4.8

Наименование

io.vertx:vertx-core

maven
Затронутые версииВерсия исправления

>= 4.5.0, < 4.5.3

4.5.3

EPSS

Процентиль: 27%
0.00098
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 5.4
redhat
около 2 лет назад

A vulnerability in the Eclipse Vert.x toolkit causes a memory leak in TCP servers configured with TLS and SNI support. When processing an unknown SNI server name assigned the default certificate instead of a mapped certificate, the SSL context is erroneously cached in the server name map, leading to memory exhaustion. This flaw allows attackers to send TLS client hello messages with fake server names, triggering a JVM out-of-memory error.

CVSS3: 5.4
nvd
почти 2 года назад

A vulnerability in the Eclipse Vert.x toolkit causes a memory leak in TCP servers configured with TLS and SNI support. When processing an unknown SNI server name assigned the default certificate instead of a mapped certificate, the SSL context is erroneously cached in the server name map, leading to memory exhaustion. This flaw allows attackers to send TLS client hello messages with fake server names, triggering a JVM out-of-memory error.

CVSS3: 5.4
fstec
около 2 лет назад

Уязвимость набора инструментов Eclipse Vert.x, связанная с утечкой памяти, позволяющая нарушителю раскрыть защищаемую информацию или вызвать отказ в обслуживании

EPSS

Процентиль: 27%
0.00098
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-400