DirectorySecurity Advisories
Sign In
Security Advisories

CGA-w9fh-6r6w-f7rr

Published

Last updated

https://images.chainguard.dev/security/CGA-w9fh-6r6w-f7rr
Package

elasticsearch-8

Latest Update
Fixed
Fixed Version

8.12.1-r0

Aliases
  • CVE-2023-34062
  • GHSA-xjhv-p3fv-x24r

Severity

7.5

High

CVSS V3

Summary

In Reactor Netty HTTP Server a malicious user can send a request using a specially crafted URL that can lead to a directory traversal attack

Description

In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, a malicious user can send a request using a specially crafted URL that can lead to a directory traversal attack.

Specifically, an application is vulnerable if Reactor Netty HTTP Server is configured to serve static resources.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images