PT-2023-8189 · Unknown · Reactor Netty Http Server +1
James Yuzawa
·
Published
2023-11-27
·
Updated
2023-12-04
·
CVE-2023-34054
7.5
High
Base vector | Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Reactor Netty HTTP Server versions 1.0.x prior to 1.0.39
Reactor Netty HTTP Server versions 1.1.x prior to 1.1.13
Description:
The issue is related to an uncontrolled resource consumption in the Reactor Netty HTTP Server, which can be exploited by a remote attacker using specially crafted HTTP requests to cause a denial-of-service (DoS) condition. This can happen if the built-in integration with Micrometer is enabled in the application.
Recommendations:
For Reactor Netty HTTP Server versions 1.0.x prior to 1.0.39, update to version 1.0.39 or later to resolve the issue.
For Reactor Netty HTTP Server versions 1.1.x prior to 1.1.13, update to version 1.1.13 or later to resolve the issue.
As a temporary workaround, consider disabling the built-in integration with Micrometer until a patch is available.
Fix
Resource Exhaustion
Weakness Enumeration
Related Identifiers
Affected Products
References · 13
- https://osv.dev/vulnerability/CVE-2023-34054 · Vendor Advisory
- https://osv.dev/vulnerability/GHSA-q24v-hpg3-v3jp · Vendor Advisory
- https://spring.io/security/cve-2023-34054 · Vendor Advisory
- https://bdu.fstec.ru/vul/2024-00178 · Security Note
- https://nvd.nist.gov/vuln/detail/CVE-2023-34054 · Security Note
- https://github.com/reactor/reactor-netty⭐ 2689 🔗 673 · Note
- https://github.com/reactor/reactor-netty/releases/tag/v1.0.39⭐ 2609 🔗 647 · Note
- https://github.com/reactor/reactor-netty/commit/ae82154e99e6f51f4816effd135f0c3a966d6ea3⭐ 2609 🔗 647 · Note
- https://github.com/reactor/reactor-netty/releases/tag/v1.1.13⭐ 2609 🔗 647 · Note
- https://github.com/reactor/reactor-netty/commit/37dc8a2ef6514cd7834e75e7f3faf0b9ea044c88⭐ 2609 🔗 647 · Note
- https://github.com/reactor/reactor-netty/commit/4ddbb1b9b985bb72290110ebae468a54e7f19420⭐ 2609 🔗 647 · Note
- https://t.me/cvenotify/62173 · Telegram Post
- https://t.me/cvenotify/61317 · Telegram Post