Описание
Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. Versions 4.7.0 through 4.10.16 used an unbounded ConcurrentHashMap cache with no eviction policy in its DefaultHtmlErrorResponseBodyProvider. If the application throws an exception whose message may be influenced by an attacker, (for example, including request query value parameters) it could be used by remote attackers to cause an unbounded heap growth and OutOfMemoryError, leading to DoS. This issue has been fixed in version 4.10.7.
A flaw was found in Micronaut Framework. Remote attackers can exploit an unbounded cache in the DefaultHtmlErrorResponseBodyProvider component by influencing exception messages, such as through request query parameters. This can lead to uncontrolled memory growth and an OutOfMemoryError, resulting in a Denial of Service (DoS) for the application.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat build of Apache Camel for Spring Boot 4 | jkube-kit-micronaut | Fix deferred | ||
| Red Hat Fuse 7 | bolt-micronaut | Fix deferred | ||
| Red Hat Fuse 7 | jkube-kit-micronaut | Fix deferred | ||
| Red Hat Fuse 7 | micronaut-aop | Fix deferred | ||
| Red Hat Fuse 7 | micronaut-buffer-netty | Fix deferred | ||
| Red Hat Fuse 7 | micronaut-context | Fix deferred | ||
| Red Hat Fuse 7 | micronaut-core | Fix deferred | ||
| Red Hat Fuse 7 | micronaut-core-reactive | Fix deferred | ||
| Red Hat Fuse 7 | micronaut-http | Fix deferred | ||
| Red Hat Fuse 7 | micronaut-http-client | Fix deferred |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. Versions 4.7.0 through 4.10.16 used an unbounded ConcurrentHashMap cache with no eviction policy in its DefaultHtmlErrorResponseBodyProvider. If the application throws an exception whose message may be influenced by an attacker, (for example, including request query value parameters) it could be used by remote attackers to cause an unbounded heap growth and OutOfMemoryError, leading to DoS. This issue has been fixed in version 4.10.7.
Micronaut Framework vulnerable to a Denial of Service in HTML error response caching
EPSS
6.5 Medium
CVSS3