Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-8447

Опубликовано: 30 сент. 2024
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

A security issue was discovered in the LRA Coordinator component of Narayana. When Cancel is called in LRA, an execution time of approximately 2 seconds occurs. If Join is called with the same LRA ID within that timeframe, the application may crash or hang indefinitely, leading to a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Data Grid 7org.jboss.narayana-narayana-allAffected
Red Hat JBoss Enterprise Application Platform 7org.jboss.narayana-narayana-allOut of support scope
Red Hat JBoss Enterprise Application Platform Expansion Packorg.jboss.narayana-narayana-allAffected
Red Hat JBoss EAP XP 5.0 Update 2.0org.jboss.narayana-narayana-allFixedRHSA-2025:762014.05.2025
Red Hat JBoss Enterprise Application Platform 8org.jboss.narayana-narayana-allFixedRHSA-2025:335827.03.2025
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8eap8-eap-product-conf-parentFixedRHSA-2025:335727.03.2025
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8eap8-nettyFixedRHSA-2025:335727.03.2025
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8eap8-netty-transport-native-epollFixedRHSA-2025:335727.03.2025
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8eap8-slf4jFixedRHSA-2025:335727.03.2025
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8eap8-wildflyFixedRHSA-2025:335727.03.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-833
https://bugzilla.redhat.com/show_bug.cgi?id=2335206narayana: deadlock via multiple join requests sent to LRA Coordinator

EPSS

Процентиль: 53%
0.00306
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
nvd
12 месяцев назад

A security issue was discovered in the LRA Coordinator component of Narayana. When Cancel is called in LRA, an execution time of approximately 2 seconds occurs. If Join is called with the same LRA ID within that timeframe, the application may crash or hang indefinitely, leading to a denial of service.

CVSS3: 5.9
github
12 месяцев назад

Narayana deadlock via multiple join requests sent to LRA Coordinator

EPSS

Процентиль: 53%
0.00306
Низкий

5.9 Medium

CVSS3