Описание
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS responses. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
Ссылки
- Release Notes
- Release Notes
- Vendor Advisory
Уязвимые конфигурации
Одно из
EPSS
8.7 High
CVSS3
10 Critical
CVSS3
Дефекты
Связанные уязвимости
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS responses. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS responses. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
Netty is a network application framework for development of protocol s ...
Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records
EPSS
8.7 High
CVSS3
10 Critical
CVSS3