[MAVEN:GHSA-RV63-GQM8-9W8Q] Loop with Unreachable Exit Condition in Netty

Severity High
Affected Packages 2
Fixed Packages 2
CVEs 1

handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (infinite loop).

Package Affected Version
pkg:maven/io.netty/netty-handler >= 4.1.0.Beta1, < 4.1.1.Final
pkg:maven/io.netty/netty-handler >= 4.0.0.Alpha1, < 4.0.37.Final
Package Fixed Version
pkg:maven/io.netty/netty-handler = 4.1.1.Final
pkg:maven/io.netty/netty-handler = 4.0.37.Final
ID
MAVEN:GHSA-RV63-GQM8-9W8Q
Severity
high
URL
https://github.com/advisories/GHSA-rv63-gqm8-9w8q
Published
2022-05-13T01:11:43
(2 years ago)
Modified
2023-10-30T20:21:10
(10 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/io.netty/netty-handler io.netty netty-handler >= 4.1.0.Beta1 < 4.1.1.Final
Fixed pkg:maven/io.netty/netty-handler io.netty netty-handler = 4.1.1.Final
Affected pkg:maven/io.netty/netty-handler io.netty netty-handler >= 4.0.0.Alpha1 < 4.0.37.Final
Fixed pkg:maven/io.netty/netty-handler io.netty netty-handler = 4.0.37.Final
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...