Red Hat build of Eclipse Vert.x
Eclipse Vert.x contains several different components designed to make it easier for you to write reactive applications. Vert.x is highly modular and you just use the bits that you need and nothing more.
browse_doc
Release Notes for Eclipse Vert.x 4.3Release Information
Supported Configurations and IntegrationsRelease Information
Eclipse Vert.x Runtime GuideRuntime Information
latest_security
| severity | advisory_cve | synopsis | date |
|---|---|---|---|
| severity Moderate | advisory_cveCVE-2022-41854 | synopsis Those using Snakeyaml to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack overflow. This effect may support a denial of service attack. | date |
| severity Moderate | advisory_cveCVE-2022-38752 | synopsis A flaw was found in the snakeyaml package due to a stack-overflow in parsing YAML files. By persuading a victim to open a specially-crafted file, a remote attacker could cause the application to crash. | date |
| severity Important | advisory_cveCVE-2022-25857 | synopsis A flaw was found in the org.yaml.snakeyaml package. This flaw allows an attacker to cause a denial of service (DoS) due to missing nested depth limitation for collections. | date |
| severity Moderate | advisory_cveCVE-2021-21295 | synopsis In Netty (io.netty:netty-codec-http2) before version 4.1.60.Final there is a vulnerability that enables request smuggling. If a Content-Length header is present in the original HTTP/2 request, the field is not validated by `Http2MultiplexHandler` as it is propagated up. This is fine as long as the request is not proxied through as HTTP/1.1. If the request comes in as an HTTP/2 stream, gets converted into the HTTP/1.1 domain objects (`HttpRequest`, `HttpContent`, etc.) via `Http2StreamFrameToHttpObjectCodec `and then sent up to the child channel's pipeline and proxied through a remote peer as HTTP/1.1 this may result in request smuggling. | date |
| severity Moderate | advisory_cveCVE-2021-21290 | synopsis In Netty there is a vulnerability on Unix-like systems involving an insecure temp file. When netty's multipart decoders are used, a local information disclosure can occur via the local system temporary directory if temporary storing uploads on the disk is enabled. On unix-like systems, the temporary directory is shared between all user. As such, writing to this directory using APIs that do not explicitly set the file/directory permissions can lead to information disclosure. | date |
top_resources
Knowledgebase
Access articles and solutions to find answers to your questions.
Lifecycle
View the various levels of maintenance for each release of a product over a period from initial release to the end of maintenance.
Component details
Self-solve an issue or learn more about issues, environments, and resolutions.
Red Hat build of Eclipse Vert.x Supported Configurations
Every Red Hat build of Eclipse Vert.x release is tested with the most recent Red Hat OpenShift Container Platform and Red Hat Enterprise Linux release.