[MAVEN:GHSA-Q24V-HPG3-V3JP] Reactor Netty HTTP Server denial of service vulnerability

Severity High
Affected Packages 3
Fixed Packages 3
CVEs 1

In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition.

Specifically, an application is vulnerable if Reactor Netty HTTP Server built-in integration with Micrometer is enabled.

ID
MAVEN:GHSA-Q24V-HPG3-V3JP
Severity
high
URL
https://github.com/advisories/GHSA-q24v-hpg3-v3jp
Published
2023-11-28T09:30:27
(9 months ago)
Modified
2023-12-05T21:45:09
(9 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/io.projectreactor.netty/reactor-netty-http io.projectreactor.netty reactor-netty-http >= 1.0.0 < 1.0.39
Fixed pkg:maven/io.projectreactor.netty/reactor-netty-http io.projectreactor.netty reactor-netty-http = 1.0.39
Affected pkg:maven/io.projectreactor.netty/reactor-netty-http io.projectreactor.netty reactor-netty-http >= 1.1.0 < 1.1.13
Fixed pkg:maven/io.projectreactor.netty/reactor-netty-http io.projectreactor.netty reactor-netty-http = 1.1.13
Affected pkg:maven/io.projectreactor.netty/reactor-netty-core io.projectreactor.netty reactor-netty-core >= 1.0.0 < 1.0.39
Fixed pkg:maven/io.projectreactor.netty/reactor-netty-core io.projectreactor.netty reactor-netty-core = 1.0.39
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...