classicvalues / qr1

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

CVE-2023-4586 (High) detected in netty-handler-4.1.86.Final.jar - autoclosed

mend-bolt-for-github opened this issue · comments

CVE-2023-4586 - High Severity Vulnerability

Vulnerable Library - netty-handler-4.1.86.Final.jar

Library home page: https://netty.io/

Path to dependency file: /service-a/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/io/netty/netty-handler/4.1.86.Final/netty-handler-4.1.86.Final.jar

Dependency Hierarchy:

  • vertx-auth-jwt-4.3.7.jar (Root Library)
    • vertx-auth-common-4.3.7.jar
      • vertx-core-4.3.7.jar
        • netty-handler-4.1.86.Final.jar (Vulnerable Library)

Found in base branch: master

Vulnerability Details

A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostname validation when using TLS, possibly resulting in a man-in-the-middle (MITM) attack.

Publish Date: 2023-10-04

URL: CVE-2023-4586

CVSS 3 Score Details (7.4)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: High
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://nvd.nist.gov/vuln/detail/CVE-2023-4586

Release Date: 2023-10-04

Fix Resolution: io.netty:netty-handler - 5.0.0.Alpha1


Step up your Open Source Security Game with Mend here

✔️ This issue was automatically closed by Mend because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the Mend inventory.