Lucene search

K
cvelistGitHub_MCVELIST:CVE-2022-41881
HistoryDec 12, 2022 - 12:00 a.m.

CVE-2022-41881

2022-12-1200:00:00
CWE-674
GitHub_M
www.cve.org
1
netty project
stackoverflowerror
vulnerability

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

7.5 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

51.7%

Netty project is an event-driven asynchronous network application framework. In versions prior to 4.1.86.Final, a StackOverflowError can be raised when parsing a malformed crafted message due to an infinite recursion. This issue is patched in version 4.1.86.Final. There is no workaround, except using a custom HaProxyMessageDecoder.

CNA Affected

[
  {
    "vendor": "netty",
    "product": "netty",
    "versions": [
      {
        "version": "< 4.1.86.Final",
        "status": "affected"
      }
    ]
  }
]

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

7.5 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

51.7%