Количество 10
Количество 10

CVE-2024-29025
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `HttpPostRequestDecoder` can be tricked to accumulate data. While the decoder can store items on the disk if configured so, there are no limits to the number of fields the form can have, an attacher can send a chunked post consisting of many small fields that will be accumulated in the `bodyListHttpData` list. The decoder cumulates bytes in the `undecodedChunk` buffer until it can decode a field, this field can cumulate data without limits. This vulnerability is fixed in 4.1.108.Final.

CVE-2024-29025
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `HttpPostRequestDecoder` can be tricked to accumulate data. While the decoder can store items on the disk if configured so, there are no limits to the number of fields the form can have, an attacher can send a chunked post consisting of many small fields that will be accumulated in the `bodyListHttpData` list. The decoder cumulates bytes in the `undecodedChunk` buffer until it can decode a field, this field can cumulate data without limits. This vulnerability is fixed in 4.1.108.Final.

CVE-2024-29025
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `HttpPostRequestDecoder` can be tricked to accumulate data. While the decoder can store items on the disk if configured so, there are no limits to the number of fields the form can have, an attacher can send a chunked post consisting of many small fields that will be accumulated in the `bodyListHttpData` list. The decoder cumulates bytes in the `undecodedChunk` buffer until it can decode a field, this field can cumulate data without limits. This vulnerability is fixed in 4.1.108.Final.
CVE-2024-29025
Netty is an asynchronous event-driven network application framework fo ...

SUSE-SU-2024:2313-1
Security update for netty3

SUSE-SU-2024:1079-2
Security update for netty, netty-tcnative

SUSE-SU-2024:1079-1
Security update for netty, netty-tcnative
GHSA-5jpm-x58v-624v
Netty's HttpPostRequestDecoder can OOM

BDU:2024-02650
Уязвимость класса HttpPostRequestDecoder сетевого программного средства Netty, позволяющая нарушителю вызвать отказ в обслуживании

ROS-20240514-04
Множественные уязвимости netty
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2024-29025 Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `HttpPostRequestDecoder` can be tricked to accumulate data. While the decoder can store items on the disk if configured so, there are no limits to the number of fields the form can have, an attacher can send a chunked post consisting of many small fields that will be accumulated in the `bodyListHttpData` list. The decoder cumulates bytes in the `undecodedChunk` buffer until it can decode a field, this field can cumulate data without limits. This vulnerability is fixed in 4.1.108.Final. | CVSS3: 5.3 | 0% Низкий | больше 1 года назад |
![]() | CVE-2024-29025 Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `HttpPostRequestDecoder` can be tricked to accumulate data. While the decoder can store items on the disk if configured so, there are no limits to the number of fields the form can have, an attacher can send a chunked post consisting of many small fields that will be accumulated in the `bodyListHttpData` list. The decoder cumulates bytes in the `undecodedChunk` buffer until it can decode a field, this field can cumulate data without limits. This vulnerability is fixed in 4.1.108.Final. | CVSS3: 5.3 | 0% Низкий | больше 1 года назад |
![]() | CVE-2024-29025 Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `HttpPostRequestDecoder` can be tricked to accumulate data. While the decoder can store items on the disk if configured so, there are no limits to the number of fields the form can have, an attacher can send a chunked post consisting of many small fields that will be accumulated in the `bodyListHttpData` list. The decoder cumulates bytes in the `undecodedChunk` buffer until it can decode a field, this field can cumulate data without limits. This vulnerability is fixed in 4.1.108.Final. | CVSS3: 5.3 | 0% Низкий | больше 1 года назад |
CVE-2024-29025 Netty is an asynchronous event-driven network application framework fo ... | CVSS3: 5.3 | 0% Низкий | больше 1 года назад | |
![]() | SUSE-SU-2024:2313-1 Security update for netty3 | 0% Низкий | 12 месяцев назад | |
![]() | SUSE-SU-2024:1079-2 Security update for netty, netty-tcnative | 0% Низкий | около 1 года назад | |
![]() | SUSE-SU-2024:1079-1 Security update for netty, netty-tcnative | 0% Низкий | около 1 года назад | |
GHSA-5jpm-x58v-624v Netty's HttpPostRequestDecoder can OOM | CVSS3: 5.3 | 0% Низкий | больше 1 года назад | |
![]() | BDU:2024-02650 Уязвимость класса HttpPostRequestDecoder сетевого программного средства Netty, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 5.3 | 0% Низкий | больше 1 года назад |
![]() | ROS-20240514-04 Множественные уязвимости netty | CVSS3: 7.5 | около 1 года назад |
Уязвимостей на страницу