Логотип exploitDog
bind: "CVE-2024-29025"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2024-29025"

Количество 10

Количество 10

ubuntu логотип

CVE-2024-29025

почти 2 года назад

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `HttpPostRequestDecoder` can be tricked to accumulate data. While the decoder can store items on the disk if configured so, there are no limits to the number of fields the form can have, an attacher can send a chunked post consisting of many small fields that will be accumulated in the `bodyListHttpData` list. The decoder cumulates bytes in the `undecodedChunk` buffer until it can decode a field, this field can cumulate data without limits. This vulnerability is fixed in 4.1.108.Final.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2024-29025

почти 2 года назад

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `HttpPostRequestDecoder` can be tricked to accumulate data. While the decoder can store items on the disk if configured so, there are no limits to the number of fields the form can have, an attacher can send a chunked post consisting of many small fields that will be accumulated in the `bodyListHttpData` list. The decoder cumulates bytes in the `undecodedChunk` buffer until it can decode a field, this field can cumulate data without limits. This vulnerability is fixed in 4.1.108.Final.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2024-29025

почти 2 года назад

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `HttpPostRequestDecoder` can be tricked to accumulate data. While the decoder can store items on the disk if configured so, there are no limits to the number of fields the form can have, an attacher can send a chunked post consisting of many small fields that will be accumulated in the `bodyListHttpData` list. The decoder cumulates bytes in the `undecodedChunk` buffer until it can decode a field, this field can cumulate data without limits. This vulnerability is fixed in 4.1.108.Final.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2024-29025

почти 2 года назад

Netty is an asynchronous event-driven network application framework fo ...

CVSS3: 5.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:2313-1

больше 1 года назад

Security update for netty3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1079-2

больше 1 года назад

Security update for netty, netty-tcnative

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1079-1

почти 2 года назад

Security update for netty, netty-tcnative

EPSS: Низкий
github логотип

GHSA-5jpm-x58v-624v

почти 2 года назад

Netty's HttpPostRequestDecoder can OOM

CVSS3: 5.3
EPSS: Низкий
fstec логотип

BDU:2024-02650

почти 2 года назад

Уязвимость класса HttpPostRequestDecoder сетевого программного средства Netty, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.3
EPSS: Низкий
redos логотип

ROS-20240514-04

больше 1 года назад

Множественные уязвимости netty

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-29025

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `HttpPostRequestDecoder` can be tricked to accumulate data. While the decoder can store items on the disk if configured so, there are no limits to the number of fields the form can have, an attacher can send a chunked post consisting of many small fields that will be accumulated in the `bodyListHttpData` list. The decoder cumulates bytes in the `undecodedChunk` buffer until it can decode a field, this field can cumulate data without limits. This vulnerability is fixed in 4.1.108.Final.

CVSS3: 5.3
0%
Низкий
почти 2 года назад
redhat логотип
CVE-2024-29025

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `HttpPostRequestDecoder` can be tricked to accumulate data. While the decoder can store items on the disk if configured so, there are no limits to the number of fields the form can have, an attacher can send a chunked post consisting of many small fields that will be accumulated in the `bodyListHttpData` list. The decoder cumulates bytes in the `undecodedChunk` buffer until it can decode a field, this field can cumulate data without limits. This vulnerability is fixed in 4.1.108.Final.

CVSS3: 5.3
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-29025

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `HttpPostRequestDecoder` can be tricked to accumulate data. While the decoder can store items on the disk if configured so, there are no limits to the number of fields the form can have, an attacher can send a chunked post consisting of many small fields that will be accumulated in the `bodyListHttpData` list. The decoder cumulates bytes in the `undecodedChunk` buffer until it can decode a field, this field can cumulate data without limits. This vulnerability is fixed in 4.1.108.Final.

CVSS3: 5.3
0%
Низкий
почти 2 года назад
debian логотип
CVE-2024-29025

Netty is an asynchronous event-driven network application framework fo ...

CVSS3: 5.3
0%
Низкий
почти 2 года назад
suse-cvrf логотип
SUSE-SU-2024:2313-1

Security update for netty3

0%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:1079-2

Security update for netty, netty-tcnative

0%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:1079-1

Security update for netty, netty-tcnative

0%
Низкий
почти 2 года назад
github логотип
GHSA-5jpm-x58v-624v

Netty's HttpPostRequestDecoder can OOM

CVSS3: 5.3
0%
Низкий
почти 2 года назад
fstec логотип
BDU:2024-02650

Уязвимость класса HttpPostRequestDecoder сетевого программного средства Netty, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.3
0%
Низкий
почти 2 года назад
redos логотип
ROS-20240514-04

Множественные уязвимости netty

CVSS3: 7.5
больше 1 года назад

Уязвимостей на страницу