Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-24823

Опубликовано: 06 мая 2022
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 1.9
CVSS3: 5.5

Описание

Netty is an open-source, asynchronous event-driven network application framework. The package io.netty:netty-codec-http prior to version 4.1.77.Final contains an insufficient fix for CVE-2021-21290. When Netty's multipart decoders are used local information disclosure can occur via the local system temporary directory if temporary storing uploads on the disk is enabled. This only impacts applications running on Java version 6 and lower. Additionally, this vulnerability impacts code running on Unix-like systems, and very old versions of Mac OSX and Windows as they all share the system temporary directory between all users. Version 4.1.77.Final contains a patch for this vulnerability. As a workaround, specify one's own java.io.tmpdir when starting the JVM or use DefaultHttpDataFactory.setBaseDir(...) to set the directory to something that is only readable by the current user.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

needed

esm-apps/bionic

released

1:4.1.7-4ubuntu0.1+esm3
esm-apps/focal

released

1:4.1.45-1ubuntu0.1~esm2
esm-apps/jammy

released

1:4.1.48-4+deb11u2ubuntu0.1~esm1
esm-apps/noble

released

1:4.1.48-9ubuntu0.1~esm1
esm-apps/xenial

released

1:4.0.34-1ubuntu0.1~esm2
esm-infra-legacy/trusty

needed

focal

ignored

end of standard support, was needed
impish

ignored

end of life

Показывать по

EPSS

Процентиль: 52%
0.00285
Низкий

1.9 Low

CVSS2

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
redhat
больше 3 лет назад

Netty is an open-source, asynchronous event-driven network application framework. The package `io.netty:netty-codec-http` prior to version 4.1.77.Final contains an insufficient fix for CVE-2021-21290. When Netty's multipart decoders are used local information disclosure can occur via the local system temporary directory if temporary storing uploads on the disk is enabled. This only impacts applications running on Java version 6 and lower. Additionally, this vulnerability impacts code running on Unix-like systems, and very old versions of Mac OSX and Windows as they all share the system temporary directory between all users. Version 4.1.77.Final contains a patch for this vulnerability. As a workaround, specify one's own `java.io.tmpdir` when starting the JVM or use DefaultHttpDataFactory.setBaseDir(...) to set the directory to something that is only readable by the current user.

CVSS3: 5.5
nvd
больше 3 лет назад

Netty is an open-source, asynchronous event-driven network application framework. The package `io.netty:netty-codec-http` prior to version 4.1.77.Final contains an insufficient fix for CVE-2021-21290. When Netty's multipart decoders are used local information disclosure can occur via the local system temporary directory if temporary storing uploads on the disk is enabled. This only impacts applications running on Java version 6 and lower. Additionally, this vulnerability impacts code running on Unix-like systems, and very old versions of Mac OSX and Windows as they all share the system temporary directory between all users. Version 4.1.77.Final contains a patch for this vulnerability. As a workaround, specify one's own `java.io.tmpdir` when starting the JVM or use DefaultHttpDataFactory.setBaseDir(...) to set the directory to something that is only readable by the current user.

CVSS3: 5.5
debian
больше 3 лет назад

Netty is an open-source, asynchronous event-driven network application ...

CVSS3: 5.5
github
больше 3 лет назад

Local Information Disclosure Vulnerability in io.netty:netty-codec-http

CVSS3: 5.5
fstec
больше 3 лет назад

Уязвимость пакета io.netty: netty-codec-http сетевого программного средства Netty, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 52%
0.00285
Низкий

1.9 Low

CVSS2

5.5 Medium

CVSS3

Уязвимость CVE-2022-24823