Allocation of Resources Without Limits or Throttling in Vert.x - CVE-2024-8391
Published: September 24, 2024
Vulnerability identifier: #VU97683
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-8391
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to the gRPC server does not limit the maximum length of message payload. A remote attacker can send multiple extremely large messages to the application and perform a denial of service (DoS) attack.
Affected software
Vert.x
JBoss Enterprise Application Platform expansion pack (EAP XP)
Red Hat OpenShift Serverless
Red Hat Integration Camel Extensions for Quarkus
Red Hat Camel for Spring Boot
JBoss Enterprise Application Platform expansion pack (EAP XP)
Red Hat OpenShift Serverless
Red Hat Integration Camel Extensions for Quarkus
Red Hat Camel for Spring Boot
How to mitigate CVE-2024-8391
Install updates from vendor's website.
Vert.x - update to 4.5.10
JBoss Enterprise Application Platform expansion pack (EAP XP) - update to 5.0 Update 1.0
Red Hat OpenShift Serverless - update to 1
Red Hat Integration Camel Extensions for Quarkus - update to 3.8.5.SP1
Red Hat Camel for Spring Boot - update to 4.4.0
JBoss Enterprise Application Platform expansion pack (EAP XP) - update to 5.0 Update 1.0
Red Hat OpenShift Serverless - update to 1
Red Hat Integration Camel Extensions for Quarkus - update to 3.8.5.SP1
Red Hat Camel for Spring Boot - update to 4.4.0