Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-47535

Опубликовано: 12 нояб. 2024
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. An unsafe reading of environment file could potentially cause a denial of service in Netty. When loaded on an Windows application, Netty attempts to load a file that does not exist. If an attacker creates such a large file, the Netty application crashes. This vulnerability is fixed in 4.1.115.

A flaw was found in Netty. An unsafe reading of the environment file could potentially cause a denial of service. When loaded on a Windows application, Netty attempts to load a file that does not exist. If an attacker creates a large file, the Netty application crashes.

Отчет

Within regulated environments, a combination of the following controls acts as a significant barrier to successfully exploiting a CWE-400: Uncontrolled Resource Consumption vulnerability and therefore downgrades the severity of this particular CVE from Moderate to Low. Red Hat restricts access to all platform information by default, granting access only after successful hard token-based multi-factor authentication (MFA) and enforcing least privilege to ensure only authorized roles can execute or modify code. The environment employs malicious code protections, including IDS/IPS and antimalware tools to detect threats and monitor resource usage, helping prevent uncontrolled consumption that could lead to system failure. Additional safeguards, such as web application firewalls and load-balancing strategies, protect against resource exhaustion and performance degradation. Event logs are centrally collected, correlated, and analyzed to support monitoring, alerting, and retention, aiding in the detection of abnormal behavior and potential denial-of-service (DoS) conditions. Static code analysis and peer reviews enforce strong input validation and error handling, reducing the likelihood of input-based DoS attacks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Clients 2io.netty/nettyNot affected
Logging Subsystem for Red Hat OpenShiftio.netty/nettyNot affected
Red Hat Build of Keycloakio.netty/nettyNot affected
Red Hat Fuse 7io.netty/nettyNot affected
Red Hat Integration Camel K 1io.netty/nettyNot affected
Red Hat JBoss Data Grid 7io.netty/nettyNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packio.netty/nettyNot affected
Red Hat Process Automation 7io.netty/nettyNot affected
Red Hat Single Sign-On 7io.netty/nettyNot affected
Red Hat build of Quarkus 3.15.3io.quarkus/quarkus-nettyFixedRHSA-2025:090005.02.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2325538netty: Denial of Service attack on windows app using Netty

EPSS

Процентиль: 42%
0.00198
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 1 года назад

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. An unsafe reading of environment file could potentially cause a denial of service in Netty. When loaded on an Windows application, Netty attempts to load a file that does not exist. If an attacker creates such a large file, the Netty application crashes. This vulnerability is fixed in 4.1.115.

CVSS3: 5.5
nvd
около 1 года назад

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. An unsafe reading of environment file could potentially cause a denial of service in Netty. When loaded on an Windows application, Netty attempts to load a file that does not exist. If an attacker creates such a large file, the Netty application crashes. This vulnerability is fixed in 4.1.115.

CVSS3: 5.5
debian
около 1 года назад

Netty is an asynchronous event-driven network application framework fo ...

suse-cvrf
около 1 года назад

Security update for aalto-xml, flatten-maven-plugin, jctools, moditect, netty, netty-tcnative

CVSS3: 5.5
github
около 1 года назад

Denial of Service attack on windows app using netty

EPSS

Процентиль: 42%
0.00198
Низкий

5.5 Medium

CVSS3