Описание
An attacker can craft a large number of unique requests that trigger a failure, exhausting the capacity of the application-wide stateful retry cache. Once the cache is full, it permanently rejects any further updates, causing all later stateful retries and circuit breakers in the application to fail.
Affected versions:
Spring Retry 2.0.0 through 2.0.12; 1.3.0 through 1.3.4.
A flaw was found in Spring Retry. A remote attacker can craft a large number of unique requests, leading to the exhaustion of the application-wide stateful retry cache. Once the cache is full, it permanently rejects further updates, causing all subsequent stateful retries and circuit breakers in the application to fail. This can result in a Denial of Service (DoS) for the application.
Отчет
Red Hat ships Spring Retry as a transitive dependency in several products. This flaw affects the stateful retry cache mechanism, where an attacker can exhaust the cache by sending a large volume of unique requests that trigger failures. Once exhausted, all subsequent stateful retries and circuit breakers permanently fail, resulting in a denial of service. However, exploitation requires high attack complexity as the attacker must craft many unique requests to fill the application-wide cache.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat build of Apache Camel 4 for Quarkus 3 | spring-retry | Fix deferred | ||
| Red Hat Data Grid 8 | spring-retry | Fix deferred | ||
| Red Hat Fuse 7 | spring-retry | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | spring-retry | Out of support scope | ||
| Red Hat OpenShift Dev Spaces | devspaces/openvsx-rhel9 | Fix deferred | ||
| Red Hat OpenShift Dev Spaces | devspaces/pluginregistry-rhel9 | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
5.9 Medium
CVSS3
Связанные уязвимости
An attacker can craft a large number of unique requests that trigger a failure, exhausting the capacity of the application-wide stateful retry cache. Once the cache is full, it permanently rejects any further updates, causing all later stateful retries and circuit breakers in the application to fail. Affected versions: Spring Retry 2.0.0 through 2.0.12; 1.3.0 through 1.3.4.
Spring Retry has Cache Exhaustion in Stateful Retries that leads to Denial of Service
EPSS
5.9 Medium
CVSS3