PT-2024-19989 · Unknown · Micronaut Framework

Mattmoss

·

Published

2024-02-08

·

Updated

2024-02-16

·

CVE-2024-23639

CVSS v3.1

5.1

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Micronaut Framework versions prior to 3.8.3
Description The issue concerns enabled but unsecured management endpoints in the Micronaut Framework, which are susceptible to drive-by localhost attacks. A malicious or compromised website can make HTTP requests to localhost, and if these endpoints are not secured, they can be triggered. This is particularly problematic in development environments where such endpoints may be enabled without security measures for ease of development. Production environments typically have unused endpoints disabled and needed endpoints secured.
Recommendations For Micronaut Framework versions prior to 3.8.3, upgrade to version 3.8.3 to address the issue. As a temporary workaround, consider disabling unsecured management endpoints or restricting access to them until the upgrade can be applied.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-23639
GHSA-583G-G682-CRXF

Affected Products

Micronaut Framework