« Volver al listado

CVE-2024-6875

Estado: AplazadaMedia (6.5)—

A vulnerability was found in the Infinispan component in Red Hat Data Grid. The REST compare API may have a buffer leak and an out of memory error can occur when sending continual requests with large POST data to the REST API.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-6875",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-6875",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-03-31T14:31:56.854512Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "secalert@redhat.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "15.0.6",
              "versionType": "semver"
            }
          ],
          "packageName": "infinispan",
          "collectionURL": "https://github.com/infinispan/infinispan",
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:jboss_data_grid:8"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Data Grid 8",
          "packageName": "infinispan",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:jboss_data_grid:7"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat JBoss Data Grid 7",
          "packageName": "infinispan",
          "collectionURL": "https://access.redhat.com/jbossnetwork/restricted/listSoftware.html",
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-03-28T21:15:17.400",
  "references": [
    {
      "url": "https://access.redhat.com/security/cve/CVE-2024-6875",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2298555",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://github.com/infinispan/infinispan/pull/12645",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://github.com/infinispan/infinispan/pull/12663",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://issues.redhat.com/browse/JDG-7169",
      "source": "secalert@redhat.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "secalert@redhat.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-401"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A vulnerability was found in the Infinispan component in Red Hat Data Grid. The REST compare API may have a buffer leak and an out of memory error can occur when sending continual requests with large POST data to the REST API."
    },
    {
      "lang": "es",
      "value": "Se detectó una vulnerabilidad en el componente Infinispan de Red Hat Data Grid. La API de comparación REST podría tener una fuga de búfer y un error de memoria insuficiente al enviar solicitudes continuas con grandes cantidades de datos POST a la API REST."
    }
  ],
  "lastModified": "2026-06-26T02:16:51.373",
  "sourceIdentifier": "secalert@redhat.com"
}