Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-6875

Опубликовано: 28 мар. 2025
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A vulnerability was found in the Infinispan component in Red Hat Data Grid. The REST compare API may have a buffer leak and an out of memory error can occur when sending continual requests with large POST data to the REST API.

Отчет

The REST endpoint is secured (= authentication is required) by default in RHDG, so it is not possible for an anonymous attacker to utilize this issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Data Grid 8infinispanAffected
Red Hat JBoss Data Grid 7infinispanWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-401
https://bugzilla.redhat.com/show_bug.cgi?id=2298555infinispan: infinispan: REST compare API has buffer leak

EPSS

Процентиль: 28%
0.001
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
9 месяцев назад

A vulnerability was found in the Infinispan component in Red Hat Data Grid. The REST compare API may have a buffer leak and an out of memory error can occur when sending continual requests with large POST data to the REST API.

CVSS3: 6.5
github
9 месяцев назад

Infinispan Potential Out of Memory Error via REST Compare API Buffer API

EPSS

Процентиль: 28%
0.001
Низкий

6.5 Medium

CVSS3