Bug 2278674 (CVE-2024-21098)

Summary: CVE-2024-21098 graalvm: unauthorized ability to cause a partial denial of service
Product: [Other] Security Response Reporter: Patrick Del Bello <pdelbell>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: adinn, anstephe, avibelli, bgeorges, chazlett, clement.escoffier, dandread, dkreling, galder.zamarreno, gsmet, hamadhan, jmartisk, jwon, lthon, max.andersen, mbabacek, mosmerov, olubyans, pgallagh, pjindal, probinso, rruss, rsvoboda, sausingh, sbiarozk, sgehwolf, tqvarnst
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
A vulnerability was found in GraalVM and Mandrel (Community Edition). Successful attacks of this vulnerability can result in the unauthorized ability to cause a partial denial of service (partial DOS).
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2277977    

Description Patrick Del Bello 2024-05-02 16:34:59 UTC
Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Compiler). Supported versions that are affected are Oracle GraalVM for JDK: 17.0.10, 21.0.2, 22; Oracle GraalVM Enterprise Edition: 20.3.13 and 21.3.9. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. CVSS 3.1 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).

Comment 9 errata-xmlrpc 2024-06-25 06:23:48 UTC
This issue has been addressed in the following products:

  Red Hat build of Quarkus 3.8 on RHEL 8

Via RHSA-2024:4079 https://access.redhat.com/errata/RHSA-2024:4079

Comment 10 errata-xmlrpc 2024-06-25 07:06:03 UTC
This issue has been addressed in the following products:

  Red Hat build of Quarkus 3.2 on RHEL 8

Via RHSA-2024:4081 https://access.redhat.com/errata/RHSA-2024:4081

Comment 12 errata-xmlrpc 2025-02-06 16:43:02 UTC
This issue has been addressed in the following products:

  RHINT Camel-K 1.10.9

Via RHSA-2025:1154 https://access.redhat.com/errata/RHSA-2025:1154