Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qq9f-q439-2574

Опубликовано: 02 янв. 2025
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

Narayana deadlock via multiple join requests sent to LRA Coordinator

A security issue was discovered in the LRA Coordinator component of Narayana. When Cancel is called in LRA, an execution time of approximately 2 seconds occurs. If Join is called with the same LRA ID within that timeframe, the application may crash or hang indefinitely, leading to a denial of service.

Пакеты

Наименование

org.jboss.narayana.rts:lra-coordinator-jar

maven
Затронутые версииВерсия исправления

< 7.1.0.Final

7.1.0.Final

EPSS

Процентиль: 53%
0.00306
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-833

Связанные уязвимости

CVSS3: 5.9
redhat
больше 1 года назад

A security issue was discovered in the LRA Coordinator component of Narayana. When Cancel is called in LRA, an execution time of approximately 2 seconds occurs. If Join is called with the same LRA ID within that timeframe, the application may crash or hang indefinitely, leading to a denial of service.

CVSS3: 5.9
nvd
12 месяцев назад

A security issue was discovered in the LRA Coordinator component of Narayana. When Cancel is called in LRA, an execution time of approximately 2 seconds occurs. If Join is called with the same LRA ID within that timeframe, the application may crash or hang indefinitely, leading to a denial of service.

EPSS

Процентиль: 53%
0.00306
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-833