[MAVEN:GHSA-RV63-GQM8-9W8Q] Loop with Unreachable Exit Condition in Netty
Severity
High
Affected Packages
2
Fixed Packages
2
CVEs
1
handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (infinite loop).
Package | Affected Version |
---|---|
pkg:maven/io.netty/netty-handler | >= 4.1.0.Beta1, < 4.1.1.Final |
pkg:maven/io.netty/netty-handler | >= 4.0.0.Alpha1, < 4.0.37.Final |
Package | Fixed Version |
---|---|
pkg:maven/io.netty/netty-handler | = 4.1.1.Final |
pkg:maven/io.netty/netty-handler | = 4.0.37.Final |
- ID
- MAVEN:GHSA-RV63-GQM8-9W8Q
- Severity
- high
- URL
- https://github.com/advisories/GHSA-rv63-gqm8-9w8q
- Published
-
2022-05-13T01:11:43
(2 years ago) - Modified
-
2023-10-30T20:21:10
(10 months ago) - Rights
- Maven Security Team
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:maven/io.netty/netty-handler | io.netty | netty-handler | >= 4.1.0.Beta1 < 4.1.1.Final | |||
Fixed | pkg:maven/io.netty/netty-handler | io.netty | netty-handler | = 4.1.1.Final | |||
Affected | pkg:maven/io.netty/netty-handler | io.netty | netty-handler | >= 4.0.0.Alpha1 < 4.0.37.Final | |||
Fixed | pkg:maven/io.netty/netty-handler | io.netty | netty-handler | = 4.0.37.Final |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |