Vulnerabilities > Pivotal > Reactor Netty > High

DATE CVE VULNERABILITY TITLE RISK
2023-11-28 CVE-2023-34054 Unspecified vulnerability in Pivotal Reactor Netty
In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable if Reactor Netty HTTP Server built-in integration with Micrometer is enabled.
network
low complexity
pivotal
7.5
2023-11-15 CVE-2023-34062 Path Traversal vulnerability in Pivotal Reactor Netty 1.0.11/1.0.23
In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, a malicious user can send a request using a specially crafted URL that can lead to a directory traversal attack. Specifically, an application is vulnerable if Reactor Netty HTTP Server is configured to serve static resources.
network
low complexity
pivotal CWE-22
7.5