PT-2023-8189 · Unknown · Reactor Netty Http Server+1
James Yuzawa
·
Publicado
2023-11-27
·
Atualizado
2026-04-27
·
CVE-2023-34054
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Reactor Netty HTTP Server versions 1.0.x prior to 1.0.39
Reactor Netty HTTP Server versions 1.1.x prior to 1.1.13
Description
The issue is related to an uncontrolled resource consumption in the Reactor Netty HTTP Server, which can be exploited by a remote attacker using specially crafted HTTP requests to cause a denial-of-service (DoS) condition. This can happen if the built-in integration with Micrometer is enabled in the application.
Recommendations
For Reactor Netty HTTP Server versions 1.0.x prior to 1.0.39, update to version 1.0.39 or later to resolve the issue.
For Reactor Netty HTTP Server versions 1.1.x prior to 1.1.13, update to version 1.1.13 or later to resolve the issue.
As a temporary workaround, consider disabling the built-in integration with Micrometer until a patch is available.
Correção
Resource Exhaustion
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Micrometer
Reactor Netty Http Server