{"id":"CVE-2024-8447","title":"A security issue was discovered in the LRA Coordinator component of Narayana","summary":"A security issue was discovered in the LRA Coordinator component of Narayana. When Cancel is called in LRA, an execution time of approximately 2 seconds occurs. If Join is called with the same LRA ID within that timeframe, the applicatio…","severity":"medium","cvss":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-833"],"published":"2025-01-02","updated":"2026-09-07","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2024-8447","references":[{"url":"https://access.redhat.com/errata/RHSA-2025:3357","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:3358","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:7620","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2024-8447","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2335206","label":"secalert@redhat.com"},{"url":"https://github.com/jbosstm/narayana/pull/2293","label":"secalert@redhat.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-8447.json"},{"url":"https://www.cve.org/CVERecord?id=CVE-2024-8447"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-8447"}],"tags":["nvd","csaf","vex","red-hat"],"epss":0.00621,"epssPercentile":0.48116,"ingestedAt":"2026-09-07T16:14:01.189Z","vendor":"Red Hat","product":"Red Hat JBoss EAP 8.0 for RHEL 8","affected":["jboss_data_grid 7","jboss_enterprise_application_platform 7","jboss_enterprise_application_platform_expansion_pack","jboss_eap_8_0_for_rhel 8","jboss_eap_8_0_for_rhel 9","jboss_eap_xp_5_0_update 2.0","jboss_enterprise_application_platform 8"],"patched":["jboss_eap_8_0_for_rhel 8","jboss_eap_8_0_for_rhel 9","jboss_eap_xp_5_0_update 2.0","jboss_enterprise_application_platform 8"],"slug":"CVE-2024-8447","body":"## Overview\n\nA security issue was discovered in the LRA Coordinator component of Narayana. When Cancel is called in LRA, an execution time of approximately 2 seconds occurs. If Join is called with the same LRA ID within that timeframe, the application may crash or hang indefinitely, leading to a denial of service.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **RHSA-2025:3357** · Red Hat · fixed in: Red Hat JBoss EAP 8.0 for RHEL 8, Red Hat JBoss EAP 8.0 for RHEL 9 · released 2025-03-27 · [advisory](https://access.redhat.com/errata/RHSA-2025:3357)\n- **RHSA-2025:7620** · Red Hat · fixed in: Red Hat JBoss EAP XP 5.0 Update 2.0 · released 2025-05-14 · [advisory](https://access.redhat.com/errata/RHSA-2025:7620)\n- **RHSA-2025:3358** · Red Hat · fixed in: Red Hat JBoss Enterprise Application Platform 8 · released 2025-03-27 · [advisory](https://access.redhat.com/errata/RHSA-2025:3358)\n- **Red Hat VEX** · Moderate · affected: Red Hat JBoss Data Grid 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat JBoss Enterprise Application Platform Expansion Pack · no fix planned: Red Hat JBoss Enterprise Application Platform 7, Red Hat JBoss Data Grid 7, Red Hat JBoss Enterprise Application Platform Expansion Pack · updated 2026-09-07 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-8447.json)","depth":"sunlit","depthScore":33,"depthScoreParts":{"impact":32.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}