Описание
A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. A remote, unauthenticated attacker can send a small crafted image declaring enormous dimensions to trigger a very large memory allocation, exhausting the JVM heap and resulting in a denial of service.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat build of Apache Camel 4 for Quarkus 3 | resteasy-core | Affected | ||
| Red Hat build of Apicurio Registry 3 | resteasy-core | Affected | ||
| Red Hat build of Debezium 3 | resteasy-core | Affected | ||
| Red Hat Build of Keycloak | resteasy-core | Affected | ||
| Red Hat Build of Keycloak | rhbk/keycloak-rhel9-operator | Affected | ||
| Red Hat build of Quarkus | resteasy-core | Affected | ||
| Red Hat Certificate System 10 | redhat-pki:10/redhat-pki | Affected | ||
| Red Hat Certificate System 11 | redhat-pki | Affected | ||
| Red Hat Enterprise Linux 10 | dogtag-pki | Affected | ||
| Red Hat Enterprise Linux 8 | pki-core:10.6/pki-core | Affected |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. A remote, unauthenticated attacker can send a small crafted image declaring enormous dimensions to trigger a very large memory allocation, exhausting the JVM heap and resulting in a denial of service.
A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. A remote, unauthenticated attacker can send a small crafted image declaring enormous dimensions to trigger a very large memory allocation, exhausting the JVM heap and resulting in a denial of service.
A flaw was found in RESTEasy's IIOImageProvider, which decodes attacke ...
7.5 High
CVSS3