跳转到帖子

Red Hat JBossEAP: Memory Allocation with Excessive Size Value (CVE-2023-3171)

recommended_posts

发布于
  • Members

Red Hat JBossEAP: Memory Allocation with Excessive Size Value (CVE-2023-3171)

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
10/05/2023
Created
09/20/2024
Added
09/19/2024
Modified
12/20/2024

Description

A flaw was found in EAP-7 during deserialization of certain classes, which permits instantiation of HashMap and HashTable with no checks on resources consumed. This issue could allow an attacker to submit malicious requests using these classes, which could eventually exhaust the heap and result in a Denial of Service.. A flaw was found in EAP-7 during deserialization of certain classes, which permits instantiation of HashMap and HashTable with no checks on resources consumed. This issue could allow an attacker to submit malicious requests using these classes, which could eventually exhaust the heap and result in a Denial of Service.

Solution(s)

  • red-hat-jboss-eap-upgrade-latest

References

  • https://attackerkb.com/topics/cve-2023-3171
  • CVE - 2023-3171
  • https://access.redhat.com/security/cve/CVE-2023-3171
  • https://bugzilla.redhat.com/show_bug.cgi?id=2213639
  • https://access.redhat.com/errata/RHSA-2023:5484
  • https://access.redhat.com/errata/RHSA-2023:5485
  • https://access.redhat.com/errata/RHSA-2023:5486
  • https://access.redhat.com/errata/RHSA-2023:5488
View more
  • 查看数 703
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…