[MAVEN:GHSA-5667-3WCH-7Q7W] Eclipse Vert.x memory leak

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

A vulnerability in the Eclipse Vert.x toolkit results in a memory leak due to using Netty FastThreadLocal data structures. Specifically, when the Vert.x HTTP client establishes connections to different hosts, triggering the memory leak. The leak can be accelerated with intimate runtime knowledge, allowing an attacker to exploit this vulnerability. For instance, a server accepting arbitrary internet addresses could serve as an attack vector by connecting to these addresses, thereby accelerating the memory leak.

Package Affected Version
pkg:maven/io.vertx/vertx-core >= 4.4.5, < 4.5.2
Package Fixed Version
pkg:maven/io.vertx/vertx-core = 4.5.2
ID
MAVEN:GHSA-5667-3WCH-7Q7W
Severity
moderate
URL
https://github.com/advisories/GHSA-5667-3wch-7q7w
Published
2024-03-27T09:30:40
(5 months ago)
Modified
2024-03-27T21:58:42
(5 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/io.vertx/vertx-core io.vertx vertx-core >= 4.4.5 < 4.5.2
Fixed pkg:maven/io.vertx/vertx-core io.vertx vertx-core = 4.5.2
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...