PT-2024-7970 · Eclipse · Eclipse Vert.X
Published
2024-02-06
·
Updated
2026-02-25
·
CVE-2024-1300
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Eclipse Vert.x (affected versions not specified)
Description
A vulnerability in the Eclipse Vert.x toolkit causes a memory leak in TCP servers configured with TLS and SNI support. When processing an unknown SNI server name, the default certificate is assigned instead of a mapped certificate, leading to the SSL context being erroneously cached in the server name map. This results in memory exhaustion, allowing attackers to send TLS client hello messages with fake server names and trigger a JVM out-of-memory error.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Resource Exhaustion
Memory Leak
Missing Release of Resource after Effective Lifetime
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Eclipse Vert.X