Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-1023

Опубликовано: 27 мар. 2024
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

A vulnerability in the Eclipse Vert.x toolkit results in a memory leak due to using Netty FastThreadLocal data structures. Specifically, when the Vert.x HTTP client establishes connections to different hosts, triggering the memory leak. The leak can be accelerated with intimate runtime knowledge, allowing an attacker to exploit this vulnerability. For instance, a server accepting arbitrary internet addresses could serve as an attack vector by connecting to these addresses, thereby accelerating the memory leak.

EPSS

Процентиль: 45%
0.00227
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-401

Связанные уязвимости

CVSS3: 6.5
redhat
около 2 лет назад

A vulnerability in the Eclipse Vert.x toolkit results in a memory leak due to using Netty FastThreadLocal data structures. Specifically, when the Vert.x HTTP client establishes connections to different hosts, triggering the memory leak. The leak can be accelerated with intimate runtime knowledge, allowing an attacker to exploit this vulnerability. For instance, a server accepting arbitrary internet addresses could serve as an attack vector by connecting to these addresses, thereby accelerating the memory leak.

CVSS3: 6.5
github
почти 2 года назад

Eclipse Vert.x memory leak

EPSS

Процентиль: 45%
0.00227
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-401