CVE-2024-8447

CVSS 3.1 Score 5.9 of 10 (medium)

Details

Published Jan 2, 2025
CWE ID 833

Summary

CVE-2024-8447 is a recently disclosed vulnerability affecting the LRA Coordinator component of Narayana. This issue arises when the Cancel function is called in a Local Transaction Resource (LRA) and the execution time is around 2 seconds. If a Join function is invoked with the same LRA ID within this timeframe, the application may experience crashes or indefinite hangs, resulting in a denial of service. This vulnerability can be exploited to disrupt the normal functioning of affected systems.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share