CVE-2024-1023 describes a memory leak vulnerability in the Eclipse Vert.x toolkit, specifically impacting the Vert.x HTTP client when establishing connections to various hosts. This medium-severity vulnerability (CVSS 6.5) has a network attack vector with low complexity, allowing an authenticated attacker to cause a denial of service through memory exhaustion. While not actively exploited in the wild and lacking public exploit code or significant community discussion, the potential for accelerated exploitation exists if a server accepts arbitrary internet addresses.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Red Hat | Red Hat Build Of Keycloak | All Versions ImpactedCNA affecteddefault affected | |
| Red Hat | Red Hat Integration Camel Quarkus 2 | All Versions ImpactedCNA affecteddefault affected | |
| Red Hat | Red Hat Build Of Apache Camel For Spring Boot 3 | All Versions ImpactedCNA affecteddefault affected | |
| Red Hat | Red Hat Integration Camel K 1 | All Versions ImpactedCNA affecteddefault affected | |
| Red Hat | Red Hat Data Grid 8 | All Versions ImpactedCNA affecteddefault affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.