Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-8391

Опубликовано: 04 сент. 2024
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

In Eclipse Vert.x version 4.3.0 to 4.5.9, the gRPC server does not limit the maximum length of message payload (Maven GAV: io.vertx:vertx-grpc-server and io.vertx:vertx-grpc-client).  This is fixed in the 4.5.10 version.  Note this does not affect the Vert.x gRPC server based grpc-java and Netty libraries (Maven GAV: io.vertx:vertx-grpc)

A flaw was found in the gRPC server in Eclipse Vert.x, which does not limit the maximum length of the message payload. This may lead to excessive memory consumption in a server or a client, causing a denial of service.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Serverlessio.vertx/vertx-grpc-serverAffected
Red Hat build of Quarkusio.vertx.vertx-grpc-serverUnder investigation
Red Hat JBoss Enterprise Application Platform 8io.vertx/vertx-grpc-clientWill not fix
Red Hat JBoss Enterprise Application Platform 8io.vertx/vertx-grpc-serverWill not fix
Red Hat JBoss Enterprise Application Platform Expansion Packio.vertx/vertx-grpcAffected
Red Hat build of Apache Camel 4 for Quarkus 3io.vertx/vertx-grpc-clientFixedRHSA-2024:705224.09.2024
Red Hat build of Apache Camel 4 for Quarkus 3io.vertx/vertx-grpc-serverFixedRHSA-2024:705224.09.2024
Red Hat build of Quarkus 3.8.6.redhatio.vertx/vertx-grpc-clientFixedRHSA-2024:643723.09.2024
Red Hat build of Quarkus 3.8.6.redhatio.vertx/vertx-grpc-serverFixedRHSA-2024:643723.09.2024
Red Hat JBoss EAP XP 5.0 Update 1.0io.vertx/vertx-grpcFixedRHSA-2025:054221.01.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2309758io.vertx:vertx-grpc-client: io.vertx:vertx-grpc-server: Vertx gRPC server does not limit the maximum message size

EPSS

Процентиль: 58%
0.00364
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 1 года назад

In Eclipse Vert.x version 4.3.0 to 4.5.9, the gRPC server does not limit the maximum length of message payload (Maven GAV: io.vertx:vertx-grpc-server and io.vertx:vertx-grpc-client).  This is fixed in the 4.5.10 version.  Note this does not affect the Vert.x gRPC server based grpc-java and Netty libraries (Maven GAV: io.vertx:vertx-grpc)

CVSS3: 5.8
github
больше 1 года назад

Vertx gRPC server does not limit the maximum message size

EPSS

Процентиль: 58%
0.00364
Низкий

7.5 High

CVSS3