Описание
Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. Versions prior to both 4.10.16 and 3.10.5 do not correctly handle descending array index order during form-urlencoded body binding in theJsonBeanPropertyBinder::expandArrayToThreshold, which allows remote attackers to cause a DoS (non-terminating loop, CPU exhaustion, and OutOfMemoryError) via crafted indexed form parameters (e.g., authors[1].name followed by authors[0].name). This issue has been fixed in versions 4.10.16 and 3.10.5.
A flaw was found in Micronaut Framework, specifically within the micronaut-core component. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by sending crafted indexed form parameters. The flaw occurs because the framework does not correctly handle descending array index order during form-urlencoded body binding, leading to a non-terminating loop, CPU exhaustion, and OutOfMemoryError.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat build of Apache Camel for Spring Boot 4 | jkube-kit-micronaut | Not affected | ||
| Red Hat Fuse 7 | bolt-micronaut | Out of support scope | ||
| Red Hat Fuse 7 | jkube-kit-micronaut | Out of support scope | ||
| Red Hat Fuse 7 | micronaut-aop | Out of support scope | ||
| Red Hat Fuse 7 | micronaut-buffer-netty | Out of support scope | ||
| Red Hat Fuse 7 | micronaut-context | Out of support scope | ||
| Red Hat Fuse 7 | micronaut-core | Out of support scope | ||
| Red Hat Fuse 7 | micronaut-core-reactive | Out of support scope | ||
| Red Hat Fuse 7 | micronaut-http | Out of support scope | ||
| Red Hat Fuse 7 | micronaut-http-client | Out of support scope |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. Versions prior to both 4.10.16 and 3.10.5 do not correctly handle descending array index order during form-urlencoded body binding in theJsonBeanPropertyBinder::expandArrayToThreshold, which allows remote attackers to cause a DoS (non-terminating loop, CPU exhaustion, and OutOfMemoryError) via crafted indexed form parameters (e.g., authors[1].name followed by authors[0].name). This issue has been fixed in versions 4.10.16 and 3.10.5.
Micronaut vulnerable to DoS via crafted form-urlencoded body binding with descending array indices
EPSS
6.5 Medium
CVSS3