V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2022-24823
DEB
Medium

Netty is an open-source, asynchronous event-driven network application framework. The package `io.netty:netty-codec-http` prior to version …

CVSS
5.5
Medium
EPSS
0.01
p59
Published
2022-01-01
Updated
2022-01-01
Description

Netty is an open-source, asynchronous event-driven network application framework. The package `io.netty:netty-codec-http` prior to version 4.1.77.Final contains an insufficient fix for CVE-2021-21290. When Netty's multipart decoders are used local information disclosure can occur via the local system temporary directory if temporary storing uploads on the disk is enabled. This only impacts applications running on Java version 6 and lower. Additionally, this vulnerability impacts code running on Unix-like systems, and very old versions of Mac OSX and Windows as they all share the system temporary directory between all users. Version 4.1.77.Final contains a patch for this vulnerability. As a workaround, specify one's own `java.io.tmpdir` when starting the JVM or use DefaultHttpDataFactory.setBaseDir(...) to set the directory to something that is only readable by the current user.

Tags · CWE
CWE-378
Affected products
Eap7Eap7-activemq-artemisEap7-activemq-artemis-nativeEap7-aesh-extensionsEap7-aesh-readlineEap7-agroalEap7-antlrEap7-apache-commons-beanutilsEap7-apache-commons-cliEap7-apache-commons-codecEap7-apache-commons-collectionsEap7-apache-commons-ioEap7-apache-commons-langEap7-apache-commons-lang2Eap7-apache-cxfEap7-apache-cxf-xjc-utilsEap7-apache-mime4jEap7-apache-sshdEap7-artemis-nativeEap7-artemis-wildfly-integration
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Timeline
2022-01-01
Published
2022-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: L
Local (L)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: L
Low (L)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: N
None (N)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.010 · p59
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
eap7Tracked
eap7-activemq-artemisTracked
eap7-activemq-artemis-nativeTracked
eap7-aesh-extensionsTracked
eap7-aesh-readlineTracked
eap7-agroalTracked
eap7-antlrTracked
eap7-apache-commons-beanutilsTracked
eap7-apache-commons-cliTracked
eap7-apache-commons-codecTracked
eap7-apache-commons-collectionsTracked
eap7-apache-commons-ioTracked
eap7-apache-commons-langTracked
eap7-apache-commons-lang2Tracked
eap7-apache-cxfTracked
eap7-apache-cxf-xjc-utilsTracked
eap7-apache-mime4jTracked
eap7-apache-sshdTracked
eap7-artemis-nativeTracked
eap7-artemis-wildfly-integrationTracked
Showing first 20 of 229
Source databases
DEB
CVE
RED
UBU
Related vulnerabilities