TROYANOSYVIRUS
Back to CVEs

CVE-2018-12541

MEDIUM
6.5

Description

In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the WebSocket HTTP upgrade implementation buffers the full http request before doing the handshake, holding the entire request body in memory. There should be a reasonnable limit (8192 bytes) above which the WebSocket gets an HTTP response with the 413 status code and the connection gets closed.

CVE Details

CVSS v3.1 Score6.5
SeverityMEDIUM
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
Published10/10/2018
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0

Affected Products

eclipse:vert.x

Weaknesses (CWE)

CWE-789CWE-119

References

https://access.redhat.com/errata/RHSA-2018:2946(af854a3a-2127-422b-91ae-364da2661108)
https://bugs.eclipse.org/bugs/show_bug.cgi?id=539170(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/eclipse-vertx/vert.x/issues/2648(af854a3a-2127-422b-91ae-364da2661108)

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.