CVE-2024-8447

Aliases:GHSA-qq9f-q439-2574
Advisory lineage Upstream: 0 Downstream: 1
Downstream
Deferred
Published: 02 Jan 2025, 20:19
Last modified:11 Nov 2025, 00:43

Vulnerability Summary

Overall Risk (default)
low
24/100
CVSS Score
5.9 MEDIUM
v3.1 (cve.org)
EPSS Score
0.17% LOW
0% probability -0.13%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

02 Jan 2025, 20:19
Published
Vulnerability first disclosed
11 Nov 2025, 00:43
Last Modified
Vulnerability information updated

Description

A security issue was discovered in the LRA Coordinator component of Narayana. When Cancel is called in LRA, an execution time of approximately 2 seconds occurs. If Join is called with the same LRA ID within that timeframe, the application may crash or hang indefinitely, leading to a denial of service.

CVSS Metrics

  • v3.1MEDIUMScore: 5.9CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.17% Percentile: 38%

Techniques & Countermeasures

  • CWE-833Deadlock

    The product contains multiple threads or executable segments that are waiting for each other to release a necessary lock, resulting in deadlock.

Affected Systems

  • org.jboss.narayana.rtslra-coordinator-jar

    < 7.1.0.Final

References (9)