Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gfh6-3pqw-x2j4

Опубликовано: 12 мар. 2025
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

SmallRye Fault Tolerance out-of-memory (OOM) issue

A flaw was found in Smallrye, where smallrye-fault-tolerance is vulnerable to an out-of-memory (OOM) issue. This vulnerability is externally triggered when calling the metrics URI. Every call creates a new object within meterMap and may lead to a denial of service (DoS) issue.

Пакеты

Наименование

io.smallrye:smallrye-fault-tolerance-core

maven
Затронутые версииВерсия исправления

>= 6.3.0, < 6.4.2

6.4.2

Наименование

io.smallrye:smallrye-fault-tolerance-core

maven
Затронутые версииВерсия исправления

>= 6.5.0, < 6.9.0

6.9.0

EPSS

Процентиль: 70%
0.00642
Низкий

7.5 High

CVSS3

Дефекты

CWE-1325

Связанные уязвимости

CVSS3: 7.5
redhat
10 месяцев назад

A flaw was found in Smallrye, where smallrye-fault-tolerance is vulnerable to an out-of-memory (OOM) issue. This vulnerability is externally triggered when calling the metrics URI. Every call creates a new object within meterMap and may lead to a denial of service (DoS) issue.

CVSS3: 7.5
nvd
10 месяцев назад

A flaw was found in Smallrye, where smallrye-fault-tolerance is vulnerable to an out-of-memory (OOM) issue. This vulnerability is externally triggered when calling the metrics URI. Every call creates a new object within meterMap and may lead to a denial of service (DoS) issue.

EPSS

Процентиль: 70%
0.00642
Низкий

7.5 High

CVSS3

Дефекты

CWE-1325