漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion
Vulnerability Description
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.xml.XmlFrameDecoder.decode() failed to preserve closing-tag parser state across invocations, so an unauthenticated remote attacker could trickle-feed repeated </ sequences that repeatedly rescanned the accumulated buffer and exhausted an EventLoop thread's CPU, causing denial of service with a maxFrameLength of 1 MB. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
未加控制的资源消耗(资源穷尽)
Vulnerability Title
Netty 资源管理错误漏洞
Vulnerability Description
Netty是Netty团队开源的一个高性能网络通信框架。 Netty 4.1.136.Final之前版本和4.2.16.Final之前版本存在资源管理错误漏洞,该漏洞源于io.netty.handler.codec.xml.XmlFrameDecoder.decode()方法未能在多次调用间保留结束标签解析器状态,可能导致未经身份验证的远程攻击者通过缓慢发送重复的</序列,反复扫描累积缓冲区并耗尽EventLoop线程CPU,造成拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A