It was found that the WebSocket HTTP upgrade implementation buffers the full http request before doing the handshake, holding the entire request body in memory. Upstream issue: https://github.com/eclipse-vertx/vert.x/issues/2648 References: https://bugs.eclipse.org/bugs/show_bug.cgi?id=539170 Upstream patch: https://github.com/eclipse-vertx/vert.x/commit/269a583330695d1418a4f5578f7169350b2e1332
This issue has been addressed in the following products: Red Hat Openshift Application Runtimes (text-only advisories) Via RHSA-2018:2946 https://access.redhat.com/errata/RHSA-2018:2946
This vulnerability is out of security support scope for the following products: * Red Hat JBoss Fuse 6 Please refer to https://access.redhat.com/support/policy/updates/jboss_notes for more details.
This issue has been addressed in the following products: Red Hat Fuse 7.7.0 Via RHSA-2020:3192 https://access.redhat.com/errata/RHSA-2020:3192