CVE-2023-34054: Reactor Netty HTTP Server Metrics DoS Vulnerability
In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable if Reactor Netty HTTP Server built-in integration with Micrometer is enabled.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-34054.
What is the title of this vulnerability?
The title of this vulnerability is Reactor Netty HTTP Server Metrics DoS Vulnerability.
What is the severity of CVE-2023-34054?
The severity of CVE-2023-34054 is medium, with a severity value of 5.3.
How does CVE-2023-34054 affect versions of Reactor Netty HTTP Server?
CVE-2023-34054 affects versions 1.0.x prior to 1.0.39 and versions 1.1.x prior to 1.1.13 of Reactor Netty HTTP Server.
How can I fix CVE-2023-34054?
To fix CVE-2023-34054, update Reactor Netty HTTP Server to version 1.0.39 or higher if using version 1.0.x, or update to version 1.1.13 or higher if using version 1.1.x.