CVE-2018-12541
Last modified
CVE-2018-12541 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the WebSocket HTTP upgrade implementation buffers the full http request before doing the handshake, holding the entire request body in memory. There should be a reasonnable limit (8192 bytes) above which the WebSocket gets an HTTP response with the 413 status code and the connection gets closed.. EPSS estimates a 2.65% chance of exploitation in the next 30 days.
Description
In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the WebSocket HTTP upgrade implementation buffers the full http request before doing the handshake, holding the entire request body in memory. There should be a reasonnable limit (8192 bytes) above which the WebSocket gets an HTTP response with the 413 status code and the connection gets closed.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Eclipse | Vert.X | >= 3.0.0, < 3.5.4 |
References
- https://access.redhat.com/errata/RHSA-2018:2946Third Party Advisory
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=539170Vendor Advisory
- https://github.com/eclipse-vertx/vert.x/issues/2648Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2946Third Party Advisory
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=539170Vendor Advisory
- https://github.com/eclipse-vertx/vert.x/issues/2648Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-12541?
How severe is CVE-2018-12541?
How do I fix CVE-2018-12541?
Are you affected by CVE-2018-12541?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
