Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-2240

Опубликовано: 12 мар. 2025
Источник: redhat
CVSS3: 7.5

Описание

A flaw was found in Smallrye, where smallrye-fault-tolerance is vulnerable to an out-of-memory (OOM) issue. This vulnerability is externally triggered when calling the metrics URI. Every call creates a new object within meterMap and may lead to a denial of service (DoS) issue.

Отчет

This vulnerability allows a remote attacker to cause an out-of-memory issue when calling the metrics URI, resulting in a denial of service. As this flaw can be triggered via the network, it has been rated with an important severity.

Меры по смягчению последствий

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apicurio Registry 2io.smallrye/smallrye-fault-tolerance-coreAffected
Red Hat build of Apicurio Registry 3io.smallrye/smallrye-fault-tolerance-coreAffected
Red Hat build of Quarkusio.smallrye/smallrye-fault-tolerance-apiimplNot affected
Red Hat Fuse 7io.smallrye/smallrye-fault-tolerance-coreOut of support scope
Red Hat Integration Camel K 1io.smallrye/smallrye-fault-tolerance-coreWill not fix
Red Hat JBoss Enterprise Application Platform 7smallrye-fault-tolerance-coreNot affected
Red Hat JBoss Enterprise Application Platform 8smallrye-fault-tolerance-coreNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packsmallrye-fault-tolerance-coreNot affected
Red Hat build of Apache Camel 4.8.5 for Spring Bootio.smallrye/smallrye-fault-tolerance-coreFixedRHSA-2025:354302.04.2025
Red Hat Build of Apache Camel 4.8 for Quarkus 3.15com.redhat.quarkus.platform/quarkus-camel-bomFixedRHSA-2025:354102.04.2025

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-1325
https://bugzilla.redhat.com/show_bug.cgi?id=2351452smallrye-fault-tolerance: SmallRye Fault Tolerance

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
10 месяцев назад

A flaw was found in Smallrye, where smallrye-fault-tolerance is vulnerable to an out-of-memory (OOM) issue. This vulnerability is externally triggered when calling the metrics URI. Every call creates a new object within meterMap and may lead to a denial of service (DoS) issue.

CVSS3: 7.5
github
10 месяцев назад

SmallRye Fault Tolerance out-of-memory (OOM) issue

7.5 High

CVSS3