MEDIUM 6.5
GHSA-2q39-w2hw-2pjm
Infinispan Potential Out of Memory Error via REST Compare API Buffer API
Details
A vulnerability was found in the Infinispan component in Red Hat Data Grid. The REST compare API may have a buffer leak and an out of memory error can occur when sending continual requests with large POST data to the REST API.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven / org.infinispan:infinispan-query
No fixed version published yet for org.infinispan:infinispan-query (maven). Pin to a known-safe version or switch to an alternative.
Maven / org.infinispan:infinispan-query
Introduced in:
0 No fixed version published yet for org.infinispan:infinispan-query (maven). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-6875 [ADVISORY]
- https://github.com/infinispan/infinispan/pull/12645 [WEB]
- https://github.com/infinispan/infinispan/pull/12663 [WEB]
- https://access.redhat.com/security/cve/CVE-2024-6875 [WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=2298555 [WEB]
- https://github.com/infinispan/infinispan [PACKAGE]
- https://issues.redhat.com/browse/JDG-7169 [WEB]