Логотип exploitDog
bind:"CVE-2024-29025"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2024-29025"

Количество 10

Количество 10

ubuntu логотип

CVE-2024-29025

больше 1 года назад

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `HttpPostRequestDecoder` can be tricked to accumulate data. While the decoder can store items on the disk if configured so, there are no limits to the number of fields the form can have, an attacher can send a chunked post consisting of many small fields that will be accumulated in the `bodyListHttpData` list. The decoder cumulates bytes in the `undecodedChunk` buffer until it can decode a field, this field can cumulate data without limits. This vulnerability is fixed in 4.1.108.Final.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2024-29025

больше 1 года назад

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `HttpPostRequestDecoder` can be tricked to accumulate data. While the decoder can store items on the disk if configured so, there are no limits to the number of fields the form can have, an attacher can send a chunked post consisting of many small fields that will be accumulated in the `bodyListHttpData` list. The decoder cumulates bytes in the `undecodedChunk` buffer until it can decode a field, this field can cumulate data without limits. This vulnerability is fixed in 4.1.108.Final.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2024-29025

больше 1 года назад

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `HttpPostRequestDecoder` can be tricked to accumulate data. While the decoder can store items on the disk if configured so, there are no limits to the number of fields the form can have, an attacher can send a chunked post consisting of many small fields that will be accumulated in the `bodyListHttpData` list. The decoder cumulates bytes in the `undecodedChunk` buffer until it can decode a field, this field can cumulate data without limits. This vulnerability is fixed in 4.1.108.Final.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2024-29025

больше 1 года назад

Netty is an asynchronous event-driven network application framework fo ...

CVSS3: 5.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:2313-1

12 месяцев назад

Security update for netty3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1079-2

около 1 года назад

Security update for netty, netty-tcnative

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1079-1

около 1 года назад

Security update for netty, netty-tcnative

EPSS: Низкий
github логотип

GHSA-5jpm-x58v-624v

больше 1 года назад

Netty's HttpPostRequestDecoder can OOM

CVSS3: 5.3
EPSS: Низкий
fstec логотип

BDU:2024-02650

больше 1 года назад

Уязвимость класса HttpPostRequestDecoder сетевого программного средства Netty, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.3
EPSS: Низкий
redos логотип

ROS-20240514-04

около 1 года назад

Множественные уязвимости netty

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-29025

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `HttpPostRequestDecoder` can be tricked to accumulate data. While the decoder can store items on the disk if configured so, there are no limits to the number of fields the form can have, an attacher can send a chunked post consisting of many small fields that will be accumulated in the `bodyListHttpData` list. The decoder cumulates bytes in the `undecodedChunk` buffer until it can decode a field, this field can cumulate data without limits. This vulnerability is fixed in 4.1.108.Final.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
redhat логотип
CVE-2024-29025

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `HttpPostRequestDecoder` can be tricked to accumulate data. While the decoder can store items on the disk if configured so, there are no limits to the number of fields the form can have, an attacher can send a chunked post consisting of many small fields that will be accumulated in the `bodyListHttpData` list. The decoder cumulates bytes in the `undecodedChunk` buffer until it can decode a field, this field can cumulate data without limits. This vulnerability is fixed in 4.1.108.Final.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-29025

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `HttpPostRequestDecoder` can be tricked to accumulate data. While the decoder can store items on the disk if configured so, there are no limits to the number of fields the form can have, an attacher can send a chunked post consisting of many small fields that will be accumulated in the `bodyListHttpData` list. The decoder cumulates bytes in the `undecodedChunk` buffer until it can decode a field, this field can cumulate data without limits. This vulnerability is fixed in 4.1.108.Final.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-29025

Netty is an asynchronous event-driven network application framework fo ...

CVSS3: 5.3
0%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:2313-1

Security update for netty3

0%
Низкий
12 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:1079-2

Security update for netty, netty-tcnative

0%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2024:1079-1

Security update for netty, netty-tcnative

0%
Низкий
около 1 года назад
github логотип
GHSA-5jpm-x58v-624v

Netty's HttpPostRequestDecoder can OOM

CVSS3: 5.3
0%
Низкий
больше 1 года назад
fstec логотип
BDU:2024-02650

Уязвимость класса HttpPostRequestDecoder сетевого программного средства Netty, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.3
0%
Низкий
больше 1 года назад
redos логотип
ROS-20240514-04

Множественные уязвимости netty

CVSS3: 7.5
около 1 года назад

Уязвимостей на страницу