CVE-2024-1023
Last modified
CVE-2024-1023 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A vulnerability in the Eclipse Vert.x toolkit results in a memory leak due to using Netty FastThreadLocal data structures. Specifically, when the Vert.x HTTP client establishes connections to different hosts, triggering the memory leak. EPSS estimates a 1.64% chance of exploitation in the next 30 days.
Description
A vulnerability in the Eclipse Vert.x toolkit results in a memory leak due to using Netty FastThreadLocal data structures. Specifically, when the Vert.x HTTP client establishes connections to different hosts, triggering the memory leak. The leak can be accelerated with intimate runtime knowledge, allowing an attacker to exploit this vulnerability. For instance, a server accepting arbitrary internet addresses could serve as an attack vector by connecting to these addresses, thereby accelerating the memory leak.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-1023?
How severe is CVE-2024-1023?
How do I fix CVE-2024-1023?
Are you affected by CVE-2024-1023?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
