DirectorySecurity Advisories
Sign In
Security Advisories

CGA-jq7c-fhw5-f756

Published

Last updated

https://images.chainguard.dev/security/CGA-jq7c-fhw5-f756
Package

elasticsearch-8

Latest Update
Fixed
Fixed Version

8.12.1-r0

Aliases
  • CVE-2023-34054
  • GHSA-q24v-hpg3-v3jp

Severity

7.5

High

CVSS V3

Summary

Reactor Netty HTTP Server denial of service vulnerability

Description

In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition.

Specifically, an application is vulnerable if Reactor Netty HTTP Server built-in integration with Micrometer is enabled.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images