REDHAT-BUG-2417718: Medium severity maven/org.lz4/lz4-java vulnerability
Out-of-bounds memory operations in org.lz4:lz4-java 1.8.0 and earlier allow remote attackers to cause denial of service and read adjacent memory via untrusted compressed input.
Out-of-bounds memory operations in org.lz4:lz4-java 1.8.0 and earlier allow remote attackers to cause denial of service and read adjacent memory via untrusted compressed input.
An application must process untrusted compressed input using org.lz4:lz4-java. Remote attackers can use that input to trigger denial of service or potentially read adjacent memory.
Version 1.8.0 and earlier are affected.
Check Maven dependencies, including transitive dependencies, for org.lz4:lz4-java at version 1.8.0 or earlier. Then identify whether the application decompresses data supplied by remote or otherwise untrusted sources.
Prioritize preventing untrusted compressed input from reaching lz4-java decompression paths, especially in remotely accessible services. The provided information does not specify an alternative mitigation.