Debian Netty vulnerabilities
23 known vulnerabilities affecting debian/netty.
Total CVEs
23
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH9MEDIUM11LOW1
Vulnerabilities
Page 2 of 2
CVE-2022-41915P4MEDIUMCVSS 6.5fixed in netty 1:4.1.48-6 (bookworm)2022
CVE-2022-41915 [MEDIUM] CVE-2022-41915: netty - Netty project is an event-driven asynchronous network application framework. Sta...
Netty project is an event-driven asynchronous network application framework. Starting in version 4.1.83.Final and prior to 4.1.86.Final, when calling `DefaultHttpHeadesr.set` with an _iterator_ of values, header value validation was not performed, allowing malicious header values in the iterator to perform HTTP Response Splitting. This issue has been patched in vers
debian
CVE-2024-29025P4MEDIUMCVSS 5.3fixed in netty 1:4.1.48-7+deb12u2 (bookworm)2024
CVE-2024-29025 [MEDIUM] CVE-2024-29025: netty - Netty is an asynchronous event-driven network application framework for rapid de...
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `HttpPostRequestDecoder` can be tricked to accumulate data. While the decoder can store items on the disk if configured so, there are no limits to the number of fields the form can have, an attacher can send a chu
debian
CVE-2021-21290P4MEDIUMCVSS 6.2fixed in netty 1:4.1.48-2 (bookworm)2021
CVE-2021-21290 [MEDIUM] CVE-2021-21290: netty - Netty is an open-source, asynchronous event-driven network application framework...
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty before version 4.1.59.Final there is a vulnerability on Unix-like systems involving an insecure temp file. When netty's multipart decoders are used local information disclosure can occur via the
debian
← Previous2 / 2