REDHAT-BUG-2309758: Medium severity Eclipse Vert.x vulnerability
In Eclipse Vert.x version 4.3.0 to 4.5.9, the gRPC server does not limit the maximum length of message payload (Maven GAV: io.vertx:vertx-grpc-server and io.vertx:vertx-grpc-client).
This is fixed in the 4.5.10 version.
Note this does not affect the Vert.x gRPC server based grpc-java and Netty libraries (Maven GAV: io.vertx:vertx-grpc)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
io.vertx:vertx-grpc-serverto a version that resolves this vulnerability.Fixed in 4.5.10 - Upgrade
Upgrade
io.vertx:vertx-grpc-clientto a version that resolves this vulnerability.Fixed in 4.5.10
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2309758?
The severity of REDHAT-BUG-2309758 is significant due to the lack of payload size restriction in the gRPC server, which could lead to potential denial of service.
How do I fix REDHAT-BUG-2309758?
To fix REDHAT-BUG-2309758, upgrade your Eclipse Vert.x version to 4.5.10 or later.
Which versions of Eclipse Vert.x are affected by REDHAT-BUG-2309758?
Eclipse Vert.x versions 4.3.0 to 4.5.9 are affected by REDHAT-BUG-2309758.
Is there a workaround for REDHAT-BUG-2309758?
Currently, there are no effective workarounds for REDHAT-BUG-2309758 other than upgrading to the fixed version.
What components are impacted by REDHAT-BUG-2309758?
The gRPC server components, specifically io.vertx:vertx-grpc-server and io.vertx:vertx-grpc-client, are impacted by REDHAT-BUG-2309758.