Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Orangedog

#35234of 53,630
7.5Total CVSS
Vulnerabilities · 1
PT-2022-12968
7.5
2022-08-26
Xnio · Xnio · CVE-2022-0084
**Name of the Vulnerable Software and Affected Versions** XNIO versions prior to 3.x **Description** A flaw was found in XNIO, specifically in the `notifyReadClosed` method, which was logging a message to another expected end. This issue allows an attacker to send flawed requests to a server, possibly causing log contention-related performance concerns or an unwanted disk fill-up. **Recommendations** For versions prior to 3.x, update to the 3.x branch of the repository to resolve the issue. As a temporary workaround, consider disabling the `notifyReadClosed` method until a patch is available. Restrict access to the affected logging functionality to minimize the risk of exploitation.