PT-2024-7970 · Eclipse · Eclipse Vert.X

Published

2024-02-06

·

Updated

2026-02-25

·

CVE-2024-1300

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:P
Name of the Vulnerable Software and Affected Versions Eclipse Vert.x (affected versions not specified)
Description A vulnerability in the Eclipse Vert.x toolkit causes a memory leak in TCP servers configured with TLS and SNI support. When processing an unknown SNI server name, the default certificate is assigned instead of a mapped certificate, leading to the SSL context being erroneously cached in the server name map. This results in memory exhaustion, allowing attackers to send TLS client hello messages with fake server names and trigger a JVM out-of-memory error.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Resource Exhaustion

Memory Leak

Missing Release of Resource after Effective Lifetime

Weakness Enumeration

Related Identifiers

BDU:2024-09483
CVE-2024-1300
GHSA-9PH3-V2VH-3QX7

Affected Products

Eclipse Vert.X