Allocation of Resources Without Limits or Throttling in Vert.x - CVE-2024-8391

 

Allocation of Resources Without Limits or Throttling in Vert.x - CVE-2024-8391

Published: September 24, 2024


Vulnerability identifier: #VU97683
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-8391
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to the gRPC server does not limit the maximum length of message payload. A remote attacker can send multiple extremely large messages to the application and perform a denial of service (DoS) attack.


Affected software

Vert.x
JBoss Enterprise Application Platform expansion pack (EAP XP)
Red Hat OpenShift Serverless
Red Hat Integration Camel Extensions for Quarkus
Red Hat Camel for Spring Boot

How to mitigate CVE-2024-8391

Install updates from vendor's website.

Vert.x - update to 4.5.10
JBoss Enterprise Application Platform expansion pack (EAP XP) - update to 5.0 Update 1.0
Red Hat OpenShift Serverless - update to 1
Red Hat Integration Camel Extensions for Quarkus - update to 3.8.5.SP1
Red Hat Camel for Spring Boot - update to 4.4.0

External References

Related Security Bulletins