CVE-2024-8447: Red Hat JBoss Data Grid 7

Medium severity, CVSS 5.9. EPSS: 0.7% chance of exploitation in the next 30 days.

A security issue was discovered in the LRA Coordinator component of Narayana. When Cancel is called in LRA, an execution time of approximately 2 seconds occurs. If Join is called with the same LRA ID within that timeframe, the application may crash or hang indefinitely, leading to a denial of service.

Affected products

  • Red Hat Red Hat JBoss Data Grid 7
  • Red Hat Red Hat JBoss Eap XP 5.0 Update 2.0
  • Red Hat Red Hat JBoss Enterprise Application Platform 7
  • Red Hat Red Hat JBoss Enterprise Application Platform 8
  • Red Hat Red Hat JBoss Enterprise Application Platform 8.0 For Rhel 8: before 0:800.6.1-1.GA_redhat_00001.1.el8eap (fixed in 0:800.6.1-1.GA_redhat_00001.1.el8eap); before 0:4.1.119-1.Final_redhat_00002.1.el8eap (fixed in 0:4.1.119-1.Final_redhat_00002.1.el8eap); before 0:2.0.16-2.redhat_00003.1.el8eap (fixed in 0:2.0.16-2.redhat_00003.1.el8eap); before 0:8.0.6-15.GA_redhat_00009.1.el8eap (fixed in 0:8.0.6-15.GA_redhat_00009.1.el8eap)
  • Red Hat Red Hat JBoss Enterprise Application Platform 8.0 For Rhel 9: before 0:800.6.1-1.GA_redhat_00001.1.el9eap (fixed in 0:800.6.1-1.GA_redhat_00001.1.el9eap); before 0:4.1.119-1.Final_redhat_00002.1.el9eap (fixed in 0:4.1.119-1.Final_redhat_00002.1.el9eap); before 0:2.0.16-2.redhat_00003.1.el9eap (fixed in 0:2.0.16-2.redhat_00003.1.el9eap); before 0:8.0.6-15.GA_redhat_00009.1.el9eap (fixed in 0:8.0.6-15.GA_redhat_00009.1.el9eap)
  • Red Hat Red Hat JBoss Enterprise Application Platform Expansion Pack

Published 2025-01-02. Last modified 2026-09-07.