CVE-2018-12541
Excessive memory allocation
6.5
MEDIUM
CVSS 3.1
EPSS 2.7%
描述
In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the WebSocket HTTP upgrade implementation buffers the full http request before doing the handshake, holding the entire request body in memory. There should be a reasonnable limit (8192 bytes) above which the WebSocket gets an HTTP response with the 413 status code and the connection gets closed.
如何修補 CVE-2018-12541
要修補 CVE-2018-12541,請將受影響套件升級到下列已修補版本。
- —升級至 3.5.4 或更新版本
CVE-2018-12541 正在被利用嗎?
低 — EPSS 為 2.7%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- >= 3.0.0, < 3.5.4
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |