Allocation of Resources Without Limits or Throttling Affecting io.vertx:vertx-grpc-server package, versions [4.3.0,4.5.10)
Threat Intelligence
EPSS
0.04% (15th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JAVA-IOVERTX-7897418
- published 5 Sep 2024
- disclosed 4 Sep 2024
- credit Unknown
Introduced: 4 Sep 2024
CVE-2024-8391 Open this link in a new tabHow to fix?
Upgrade io.vertx:vertx-grpc-server
to version 4.5.10 or higher.
Overview
Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling due to the lack of a maximum message size limit. An attacker can cause a denial of service by sending excessively large messages.
Note This vulnerability does not affect the Vert.x gRPC server based grpc-java and Netty libraries (Maven GAV: io.vertx:vertx-grpc
)