Início
Início
Tendências
Tendências
Vulnerabilidades
Vulnerabilidades
Notícias
Notícias
Pesquisadores
Pesquisadores
Por que dbugs?
Por que dbugs?
Configurações

Dr. Michael Ummels

Pesquisador deBVU Beratergruppe Verkehr + Umwelt GmbH
#34068de 56,330
7.8CVSS total
Vulnerabilidades · 1
PT-2023-8190
7.8
2023-11-15
Unknown · Reactor Netty Http Server · CVE-2023-34062
**Name of the Vulnerable Software and Affected Versions** Reactor Netty HTTP Server versions 1.0.x prior to 1.0.39 Reactor Netty HTTP Server versions 1.1.x prior to 1.1.13 **Description** The issue is related to incorrect restriction of directory path names, which can lead to a directory traversal attack. This can allow a remote attacker to disclose protected information. Specifically, an application is vulnerable if Reactor Netty HTTP Server is configured to serve static resources. **Recommendations** For Reactor Netty HTTP Server versions 1.0.x prior to 1.0.39, update to version 1.0.39 or later. For Reactor Netty HTTP Server versions 1.1.x prior to 1.1.13, update to version 1.1.13 or later. As a temporary workaround, consider disabling the serving of static resources until a patch is available.