V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2018-12541
CVE
MediumConfirmedExploit available

In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the WebSocket HTTP upgrade implementation buffers the full http request before doing the …

CVSS
6.5
Medium
EPSS
0.01
p80
Published
2018-01-01
Updated
2018-01-01
Description

In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the WebSocket HTTP upgrade implementation buffers the full http request before doing the handshake, holding the entire request body in memory. There should be a reasonnable limit (8192 bytes) above which the WebSocket gets an HTTP response with the 413 status code and the connection gets closed.

Tags · CWE
CWE-770
CWE-789
CAPEC-125
CAPEC-130
CAPEC-147
CAPEC-197
CAPEC-229
CAPEC-230
CAPEC-231
CAPEC-469
CAPEC-482
CAPEC-486
CAPEC-487
CAPEC-488
CAPEC-489
CAPEC-490
CAPEC-491
CAPEC-493
CAPEC-494
CAPEC-495
CAPEC-496
CAPEC-528
Affected products
Vert.x 3.0.0–3.5.4
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Timeline
2018-01-01
Published
2018-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: L
Low (L)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: N
None (N)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.013 · p80
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-125 · CWE-770
└ via CAPEC-490 · CWE-770
└ via CAPEC-125 · CWE-770
└ via CAPEC-482 · CWE-770
└ via CAPEC-469 · CWE-770
└ via CAPEC-130 · CWE-770
Known exploits — Сканер-ВС
CVE-2018-12541
github-poc · https://github.com/dawetmaster/CVE-2018-12541-vert.x-vulnerable
Enterprise
Affected software
ProductVendorStatus
vert.x*Tracked
Source databases
CVE