In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable if Reactor Netty HTTP Server built-in integration with Micrometer is enabled.
References
Link Resource
https://spring.io/security/cve-2023-34054 Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: vmware

Published: 2023-11-28T08:16:14.361Z

Updated: 2023-11-28T08:16:57.848Z

Reserved: 2023-05-25T17:21:56.203Z


Link: CVE-2023-34054

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-11-28T09:15:07.147

Modified: 2023-12-04T19:59:30.713


Link: CVE-2023-34054

JSON object: View

cve-icon Redhat Information

No data.