CVE-2018-12541
Last modified
CVE-2018-12541 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the WebSocket HTTP upgrade implementation buffers the full http request before doing the handshake, holding the entire request body in memory. There should be a reasonnable limit (8192 bytes) above which the WebSocket gets an HTTP response with the 413 status code and the connection gets closed.. EPSS estimates a 2.65% chance of exploitation in the next 30 days.
Description
In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the WebSocket HTTP upgrade implementation buffers the full http request before doing the handshake, holding the entire request body in memory. There should be a reasonnable limit (8192 bytes) above which the WebSocket gets an HTTP response with the 413 status code and the connection gets closed.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Eclipse | Vert.X | >= 3.0.0, < 3.5.4 |
References
- https://access.redhat.com/errata/RHSA-2018:2946Third Party Advisory
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=539170Vendor Advisory
- https://github.com/eclipse-vertx/vert.x/issues/2648Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2946Third Party Advisory
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=539170Vendor Advisory
- https://github.com/eclipse-vertx/vert.x/issues/2648Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-12541?
How severe is CVE-2018-12541?
How do I fix CVE-2018-12541?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-12536In Eclipse Jetty Server, all 9.x versions, on webapps deploy…5.3
- CVE-2018-12537In Eclipse Vert.x version 3.0 to 3.5.1, the HttpServer respo…
- CVE-2018-12538In Eclipse Jetty versions 9.4.0 through 9.4.8, when using th…
- CVE-2018-12539In Eclipse OpenJ9 version 0.8, users other than the process …
- CVE-2018-1254RSA Authentication Manager Security Console, versions 8.3 P1…
- CVE-2018-12540In version from 3.0.0 to 3.5.2 of Eclipse Vert.x, the CSRFHa…
- CVE-2018-12542In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the Static…
- CVE-2018-12543In Eclipse Mosquitto versions 1.5 to 1.5.2 inclusive, if a m…
- CVE-2018-12544In version from 3.5.Beta1 to 3.5.3 of Eclipse Vert.x, the Op…
- CVE-2018-12545In Eclipse Jetty version 9.3.x and 9.4.x, the server is vuln…7.5
- CVE-2018-12546In Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) when a…6.5
- CVE-2018-12547In Eclipse OpenJ9, prior to the 0.12.0 release, the jio_snpr…
Are you affected by CVE-2018-12541?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
