CVE-2024-8447 describes a denial-of-service vulnerability in the LRA Coordinator component of Narayana. An attacker can trigger this by repeatedly calling "Cancel" and "Join" with the same LRA ID within a two-second window, causing the application to crash or hang indefinitely. This medium-severity vulnerability (CVSS 5.9) has a network attack vector and high impact on availability, but requires high attack complexity. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Red Hat | Red Hat JBoss Enterprise Application Platform 8.0 For RHEL 8 | Range not provided by sourceCNA affecteddefault affected | |
| Red Hat | Red Hat JBoss Enterprise Application Platform 8.0 For RHEL 9 | Range not provided by sourceCNA affecteddefault affected | |
| Red Hat | Red Hat JBoss Data Grid 7 | All Versions ImpactedCNA affecteddefault affected | |
| Red Hat | Red Hat JBoss Enterprise Application Platform 7 | Range not provided by sourceCNA affecteddefault unknown | |
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | All Versions ImpactedCNA affecteddefault affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.