Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-34062

Опубликовано: 15 нояб. 2023
Источник: redhat
CVSS3: 7.5

Описание

In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, a malicious user can send a request using a specially crafted URL that can lead to a directory traversal attack. Specifically, an application is vulnerable if Reactor Netty HTTP Server is configured to serve static resources.

A flaw was found in the Reactor Netty HTTP Server. If the server is configured to serve static resources, an attacker can use a specially crafted URL that may allow unauthorized access to privileged data on the server.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel for Spring Boot 3reactor-netty-httpNot affected
Red Hat build of Debezium 2reactor-netty-httpNot affected
Red Hat Fuse 7reactor-netty-httpNot affected
Red Hat Integration Camel K 1reactor-netty-httpNot affected
Red Hat JBoss Enterprise Application Platform 7reactor-netty-httpNot affected
Red Hat JBoss Enterprise Application Platform 8reactor-netty-httpNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packreactor-netty-httpNot affected
Red Hat OpenShift Dev Spacesreactor-netty-httpAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2250160reactor-netty-http: directory traversal vulnerability

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
около 2 лет назад

In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, a malicious user can send a request using a specially crafted URL that can lead to a directory traversal attack. Specifically, an application is vulnerable if Reactor Netty HTTP Server is configured to serve static resources.

CVSS3: 7.5
github
около 2 лет назад

In Reactor Netty HTTP Server a malicious user can send a request using a specially crafted URL that can lead to a directory traversal attack

CVSS3: 7.5
fstec
около 2 лет назад

Уязвимость HTTP-сервера Reactor Netty, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю раскрыть защищаемую информацию

7.5 High

CVSS3