Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-8391

Опубликовано: 04 сент. 2024
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

In Eclipse Vert.x version 4.3.0 to 4.5.9, the gRPC server does not limit the maximum length of message payload (Maven GAV: io.vertx:vertx-grpc-server and io.vertx:vertx-grpc-client).  This is fixed in the 4.5.10 version.  Note this does not affect the Vert.x gRPC server based grpc-java and Netty libraries (Maven GAV: io.vertx:vertx-grpc)

A flaw was found in the gRPC server in Eclipse Vert.x, which does not limit the maximum length of the message payload. This may lead to excessive memory consumption in a server or a client, causing a denial of service.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Serverlessvertx-grpc-clientAffected
Red Hat build of Quarkusio.vertx.vertx-grpc-serverAffected
Red Hat JBoss Enterprise Application Platform 8vertx-grpc-clientWill not fix
Red Hat JBoss Enterprise Application Platform 8vertx-grpc-serverWill not fix
Red Hat JBoss Enterprise Application Platform Expansion Packvertx-grpcAffected
Red Hat build of Apache Camel 4 for Quarkus 3vertx-grpc-clientFixedRHSA-2024:705224.09.2024
Red Hat build of Apache Camel 4 for Quarkus 3vertx-grpc-serverFixedRHSA-2024:705224.09.2024
Red Hat build of Quarkus 3.8.6.redhatio.vertx/vertx-grpc-clientFixedRHSA-2024:643723.09.2024
Red Hat build of Quarkus 3.8.6.redhatio.vertx/vertx-grpc-serverFixedRHSA-2024:643723.09.2024
Red Hat JBoss EAP XP 5.0 Update 1.0vertx-grpcFixedRHSA-2025:054221.01.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2309758io.vertx:vertx-grpc-client: io.vertx:vertx-grpc-server: Vertx gRPC server does not limit the maximum message size

EPSS

Процентиль: 45%
0.0058
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
почти 2 года назад

In Eclipse Vert.x version 4.3.0 to 4.5.9, the gRPC server does not limit the maximum length of message payload (Maven GAV: io.vertx:vertx-grpc-server and io.vertx:vertx-grpc-client).  This is fixed in the 4.5.10 version.  Note this does not affect the Vert.x gRPC server based grpc-java and Netty libraries (Maven GAV: io.vertx:vertx-grpc)

CVSS3: 5.8
github
почти 2 года назад

Vertx gRPC server does not limit the maximum message size

EPSS

Процентиль: 45%
0.0058
Низкий

7.5 High

CVSS3