opfab / operatorfabric-core

Main operatorfabric program
https://opfab.github.io
Mozilla Public License 2.0
40 stars 27 forks source link

CVE-2022-41881 (High) detected in netty-codec-haproxy-4.1.79.Final.jar - autoclosed #3944

Closed mend-bolt-for-github[bot] closed 1 year ago

mend-bolt-for-github[bot] commented 1 year ago

CVE-2022-41881 - High Severity Vulnerability

Vulnerable Library - netty-codec-haproxy-4.1.79.Final.jar

Library home page: https://netty.io/

Path to dependency file: /src/test/api/karate/karateTests.gradle

Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/io.netty/netty-codec-haproxy/4.1.79.Final/6b36a21ae4b97c4ee90f450b89f358fd36461e73/netty-codec-haproxy-4.1.79.Final.jar

Dependency Hierarchy: - karate-junit5-1.3.1.jar (Root Library) - karate-core-1.3.1.jar - armeria-1.18.0.jar - :x: **netty-codec-haproxy-4.1.79.Final.jar** (Vulnerable Library)

Found in base branch: develop

Vulnerability Details

Netty project is an event-driven asynchronous network application framework. In versions prior to 4.1.86.Final, a StackOverflowError can be raised when parsing a malformed crafted message due to an infinite recursion. This issue is patched in version 4.1.86.Final. There is no workaround, except using a custom HaProxyMessageDecoder.

Publish Date: 2022-12-12

URL: CVE-2022-41881

CVSS 3 Score Details (7.5)

Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: None - Integrity Impact: None - Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2022-12-12

Fix Resolution: io.netty:netty-codec-haproxy:netty-4.1.86.Final


Step up your Open Source Security Game with Mend here

mend-bolt-for-github[bot] commented 1 year ago

:heavy_check_mark: This issue was automatically closed by Mend because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the Mend inventory.