In Eclipse Vert.x version 4.3.0 to 4.5.9, the gRPC server does not limit the maximum length of message payload (Maven GAV: io.vertx:vertx-grpc-server and io.vertx:vertx-grpc-client). 




This is fixed in the 4.5.10 version. 




Note this does not affect the Vert.x gRPC server based grpc-java and Netty libraries (Maven GAV: io.vertx:vertx-grpc)
Advisories
Source ID Title
EUVD EUVD EUVD-2024-2795 In Eclipse Vert.x version 4.3.0 to 4.5.9, the gRPC server does not limit the maximum length of message payload (Maven GAV: io.vertx:vertx-grpc-server and io.vertx:vertx-grpc-client).  This is fixed in the 4.5.10 version.  Note this does not affect the Vert.x gRPC server based grpc-java and Netty libraries (Maven GAV: io.vertx:vertx-grpc)
Github GHSA Github GHSA GHSA-g76f-gjfx-4rpr Vertx gRPC server does not limit the maximum message size
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 13 Feb 2025 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat jboss Enterprise Application Platform
CPEs cpe:/a:redhat:jboss_enterprise_application_platform:8.0
Vendors & Products Redhat jboss Enterprise Application Platform

Tue, 15 Oct 2024 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat openshift Serverless
CPEs cpe:/a:redhat:openshift_serverless:1.34::el8
Vendors & Products Redhat openshift Serverless

Wed, 25 Sep 2024 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat camel Quarkus
CPEs cpe:/a:redhat:camel_quarkus:3.8
Vendors & Products Redhat camel Quarkus

Mon, 23 Sep 2024 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat quarkus
CPEs cpe:/a:redhat:quarkus:3.8::el8
Vendors & Products Redhat
Redhat quarkus

Thu, 12 Sep 2024 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Eclipse
Eclipse vert.x
CPEs cpe:2.3:a:eclipse:vert.x:*:*:*:*:*:*:*:*
Vendors & Products Eclipse
Eclipse vert.x
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Wed, 04 Sep 2024 21:45:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

threat_severity

Moderate


Wed, 04 Sep 2024 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Eclipse Foundation
Eclipse Foundation vert.x
CPEs cpe:2.3:a:eclipse_foundation:vert.x:*:*:*:*:*:*:*:*
Vendors & Products Eclipse Foundation
Eclipse Foundation vert.x
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 04 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
Description In Eclipse Vert.x version 4.3.0 to 4.5.9, the gRPC server does not limit the maximum length of message payload (Maven GAV: io.vertx:vertx-grpc-server and io.vertx:vertx-grpc-client).  This is fixed in the 4.5.10 version.  Note this does not affect the Vert.x gRPC server based grpc-java and Netty libraries (Maven GAV: io.vertx:vertx-grpc)
Title Eclipse Vert.x gRPC server does not limit the maximum message size
Weaknesses CWE-770
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: eclipse

Published:

Updated: 2024-09-04T17:40:20.318Z

Reserved: 2024-09-03T12:39:46.456Z

Link: CVE-2024-8391

cve-icon Vulnrichment

Updated: 2024-09-04T15:58:33.500Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-04T16:15:09.253

Modified: 2024-09-12T16:44:01.247

Link: CVE-2024-8391

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-09-04T16:15:09Z

Links: CVE-2024-8391 - Bugzilla

cve-icon OpenCVE Enrichment

No data.