Описание
In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (DoS) condition.
Affected versions:
Micrometer 1.16.0 through 1.16.5; 1.15.0 through 1.15.11.
A flaw was found in Micrometer. A remote attacker can provide specially crafted gRPC (gRPC Remote Procedure Call) requests, which may lead to a denial-of-service (DoS) condition. This vulnerability allows an attacker to disrupt the availability of the affected system.
Отчет
This is an Important denial-of-service vulnerability in Micrometer, as a remote unauthenticated attacker can disrupt the availability of affected systems by sending specially crafted gRPC requests. The broad accessibility of gRPC endpoints in typical deployments contributes to the elevated risk, allowing for significant service interruption.
Меры по смягчению последствий
To mitigate this issue, restrict network access to services exposing Micrometer's gRPC endpoints to trusted clients only. Implement firewall rules to limit inbound connections to the specific ports used by gRPC. If gRPC functionality is not essential for the deployment, consider disabling it entirely to eliminate the attack vector. Any changes to network configurations or service settings may require a service restart to take effect, potentially impacting availability during the transition.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat AMQ Broker 7 | micrometer-core | Affected | ||
| Red Hat AMQ Clients | micrometer-core | Affected | ||
| Red Hat build of Apache Camel 4 for Quarkus 3 | micrometer-core | Affected | ||
| Red Hat build of Apache Camel for Spring Boot 4 | micrometer-core | Not affected | ||
| Red Hat build of Apache Camel - HawtIO 4 | micrometer-core | Affected | ||
| Red Hat build of Apicurio Registry 3 | micrometer-core | Fix deferred | ||
| Red Hat build of Debezium 3 | micrometer-core | Not affected | ||
| Red Hat Build of Keycloak | micrometer-core | Affected | ||
| Red Hat Build of Keycloak | rhbk/keycloak-rhel9 | Affected | ||
| Red Hat Build of Keycloak | rhbk/keycloak-rhel9-operator | Affected |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (DoS) condition. Affected versions: Micrometer 1.16.0 through 1.16.5; 1.15.0 through 1.15.11.
In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (DoS) condition. Affected versions: Micrometer 1.16.0 through 1.16.5; 1.15.0 through 1.15.11.
Уязвимость java-библиотеки Micrometer фреймворка создания веб-приложений Spring Boot, позволяющая нарушителю вызвать отказ в обслуживании
7.5 High
CVSS3