Exploit Report

Computer Security And Bug Information

CVE-2024-1300

CVECVE-2024-1300
CVE Title
Published Date2024-04-02T08:15Z
Modified Date2024-04-09T12:15Z
CWE TypeCWE-400
DescriptionA vulnerability in the Eclipse Vert.x toolkit causes a memory leak in TCP servers configured with TLS and SNI support. When processing an unknown SNI server name assigned the default certificate instead of a mapped certificate, the SSL context is erroneously cached in the server name map, leading to memory exhaustion. This flaw allows attackers to send TLS client hello messages with fake server names, triggering a JVM out-of-memory error.
References
By clicking these links you will leave this website. We do not endorse and will not be held accountable for any activity on external sites.
Reference URLhttps://access.redhat.com/security/cve/CVE-2024-1300
Reference Description https://access.redhat.com/security/cve/CVE-2024-1300
Reference URLhttps://bugzilla.redhat.com/show_bug.cgi?id=2263139
Reference Description RHBZ#2263139
Reference URLhttps://vertx.io/docs/vertx-core/java/#_server_name_indication_sni.
Reference Description https://vertx.io/docs/vertx-core/java/#_server_name_indication_sni.
Reference URLhttps://access.redhat.com/errata/RHSA-2024:1662
Reference Description RHSA-2024:1662
Reference URLhttps://access.redhat.com/errata/RHSA-2024:1706
Reference Description RHSA-2024:1706
Sources NIST MITRE
Note
  • No CVSS data for this CVE

This site's data is aggregated programmatically and provided "as is" without any representations or warranties, express or implied. Exploit.report is not affiliated with the The MITRE Corporation, U.S. Department of Homeland Security (DHS), Cybersecurity and Infrastructure Security Agency (CISA), or US government in any way. CVE and the CVE logo are registered trademarks of The MITRE Corporation

© 2022 Exploit.Report | Data | Contact | Privacy Policy | Articles