CVE-2024-1300
unknown
CVSS v3
—
CVSS v2
—
VIR risk
—
Description
Eclipse Vert.x vulnerable to a memory leak in TCP servers
Predictions
Exploit likelihood
30%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Maven | io.vertx:vertx-core | >=4.3.4,<4.4.8 | 4.4.8 |
| Maven | io.vertx:vertx-core | >=4.5.0,<4.5.3 | 4.5.3 |
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-1300
- https://github.com/eclipse-vertx/vert.x/pull/5101
- https://github.com/eclipse-vertx/vert.x/pull/5100
- https://github.com/eclipse-vertx/vert.x/pull/5099
- https://github.com/eclipse-vertx/vert.x/commit/7ad34ea9d78f85e26b231ee3ec8d492d10046479
- https://github.com/eclipse-vertx/vert.x/commit/3d9235cadf44df39a70dc75bddfe0b8fcbd6a683
- https://vertx.io/docs/vertx-core/java/#_server_name_indication_sni.
- https://github.com/eclipse-vertx/vert.x
- https://bugzilla.redhat.com/show_bug.cgi?id=2263139
- https://access.redhat.com/security/cve/CVE-2024-1300
- https://access.redhat.com/errata/RHSA-2024:4884
- https://access.redhat.com/errata/RHSA-2024:3989
- https://access.redhat.com/errata/RHSA-2024:3527
- https://access.redhat.com/errata/RHSA-2024:2833
- https://access.redhat.com/errata/RHSA-2024:2088
- https://access.redhat.com/errata/RHSA-2024:1923
- https://access.redhat.com/errata/RHSA-2024:1706
- https://access.redhat.com/errata/RHSA-2024:1662
Verify integrity in audit chain (admin only). AS-IS.