跳转到帖子

Red Hat JBossEAP: Missing Release of Memory after Effective Lifetime (CVE-2024-41172)

recommended_posts

发布于
  • Members

Red Hat JBossEAP: Missing Release of Memory after Effective Lifetime (CVE-2024-41172)

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
07/19/2024
Created
09/20/2024
Added
09/19/2024
Modified
12/20/2024

Description

In versions of Apache CXF before 3.6.4 and 4.0.5 (3.5.x and lower versions are not impacted), a CXF HTTP client conduit may prevent HTTPClient instances from being garbage collected and it is possible that memory consumption will continue to increase, eventually causing the application to runout of memory. A memory consumption flaw was found in Apache CXF. This issue may allow a CXF HTTP client conduit to prevent HTTPClient instances from being garbage collected, eventually causing the application to run out of memory.

Solution(s)

  • red-hat-jboss-eap-upgrade-latest

References

  • https://attackerkb.com/topics/cve-2024-41172
  • CVE - 2024-41172
  • https://access.redhat.com/security/cve/CVE-2024-41172
  • https://bugzilla.redhat.com/show_bug.cgi?id=2298829
  • https://github.com/advisories/GHSA-4mgg-fqfq-64hg
  • https://lists.apache.org/thread/n2hvbrgwpdtcqdccod8by28ynnolybl6
  • https://osv.dev/vulnerability/GHSA-4mgg-fqfq-64hg
  • https://access.redhat.com/errata/RHSA-2024:8823
  • https://access.redhat.com/errata/RHSA-2024:8824
  • https://access.redhat.com/errata/RHSA-2024:8826
View more
  • 查看数 696
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…