SCA: security update for io.vertx:vertx-core (GHSA-5667-3wch-7q7w)

medium Tenable Cloud Security Plugin ID 410618

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- A vulnerability in the Eclipse Vert.x toolkit results in a memory leak due to using Netty FastThreadLocal
data structures. Specifically, when the Vert.x HTTP client establishes connections to different hosts,
triggering the memory leak. The leak can be accelerated with intimate runtime knowledge, allowing an
attacker to exploit this vulnerability. For instance, a server accepting arbitrary internet addresses
could serve as an attack vector by connecting to these addresses, thereby accelerating the memory leak.
(CVE-2024-1023)

See Also

https://github.com/advisories/GHSA-5667-3wch-7q7w

Plugin Details

Severity: Medium

ID: 410618

Version: Revision 1.14

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.92

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2024-1023

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 3/27/2024

Vulnerability Publication Date: 3/27/2024

Reference Information

CVE: CVE-2024-1023