Lucene search

K
githubGitHub Advisory DatabaseGHSA-9QGC-P27W-3HJG
HistoryOct 22, 2018 - 8:37 p.m.

High severity vulnerability that affects com.typesafe.akka:akka-http-core_2.11 and com.typesafe.akka:akka-http-core_2.12

2018-10-2220:37:07
CWE-400
GitHub Advisory Database
github.com
12

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.006

Percentile

79.3%

The decodeRequest and decodeRequestWith directives in Lightbend Akka HTTP 10.1.x through 10.1.4 and 10.0.x through 10.0.13 allow remote attackers to cause a denial of service (memory consumption and daemon crash) via a ZIP bomb.

Affected configurations

Vulners
Node
com.typesafe.akkaakka-http-core_2.11Range10.1.010.1.4
OR
com.typesafe.akkaakka-http-core_2.12Range10.1.010.1.4
VendorProductVersionCPE
com.typesafe.akkaakka-http-core_2.11*cpe:2.3:a:com.typesafe.akka:akka-http-core_2.11:*:*:*:*:*:*:*:*
com.typesafe.akkaakka-http-core_2.12*cpe:2.3:a:com.typesafe.akka:akka-http-core_2.12:*:*:*:*:*:*:*:*

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.006

Percentile

79.3%

Related for GHSA-9QGC-P27W-3HJG