The vendor explicitly identifies these products as affected by this CVE.
- smallrye-fault-tolerance-core as a component of Red Hat build of Apicurio Registry 2
- smallrye-fault-tolerance-core as a component of Red Hat Fuse 7
- smallrye-fault-tolerance-core as a component of Red Hat Integration Camel K 1
- smallrye-fault-tolerance-core as a component of Red Hat JBoss Enterprise Application Platform 7
- Summary
- A flaw was found in Smallrye, where smallrye-fault-tolerance is vulnerable to an out-of-memory (OOM) issue. This vulnerability is externally triggered when calling the metrics URI. Every call creates a new object within meterMap and may lead to a denial of service (DoS) issue.
- Remediation
- Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update).
