REDHAT-BUG-2351452: High severity Smallrye smallrye-fault-tolerance vulnerability
A flaw was found in Smallrye. smallrye-fault-tolerance is vulnerable to an Out-of-Memory (OOM) which is triggered externally when calling the metrics URI. Every call creates a new object within meterMap and may lead to Denial of Service (DoS).
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2351452?
REDHAT-BUG-2351452 is classified as a Denial of Service (DoS) vulnerability due to its potential to exhaust memory resources.
How do I fix REDHAT-BUG-2351452?
To mitigate REDHAT-BUG-2351452, consider limiting the rate of calls to the metrics URI and monitoring memory usage.
What impact does REDHAT-BUG-2351452 have on Smallrye?
REDHAT-BUG-2351452 can lead to an Out-of-Memory (OOM) error, resulting in a Denial of Service (DoS) affecting application availability.
Which version of Smallrye is affected by REDHAT-BUG-2351452?
All versions of Smallrye smallrye-fault-tolerance are affected by REDHAT-BUG-2351452.
How can I identify if my application is vulnerable to REDHAT-BUG-2351452?
You can identify vulnerability to REDHAT-BUG-2351452 by monitoring for excessive memory usage or crashes resulting from high-frequency calls to the metrics URI.