QID 981498
QID 981498: Java (maven) Security Update for io.vertx:vertx-core (GHSA-45xm-v8gq-7jqx)
In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the WebSocket HTTP upgrade implementation buffers the full http request before doing the handshake, holding the entire request body in memory. There should be a reasonnable limit (8192 bytes) above which the WebSocket gets an HTTP response with the 413 status code and the connection gets closed.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-45xm-v8gq-7jqx for updates pertaining to this vulnerability.
Vendor References
- GHSA-45xm-v8gq-7jqx -
github.com/advisories/GHSA-45xm-v8gq-7jqx
CVEs related to QID 981498
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-45xm-v8gq-7jqx | io.vertx:vertx-core |
|