Reactor Netty HTTP Server Metrics DoS Vulnerability

MEDIUM | NOVEMBER 27, 2023 | CVE-2023-34054

Description

In Reactor Netty HTTP Server, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition.

Specifically, an application is vulnerable if Reactor Netty HTTP Server built-in integration with Micrometer is enabled.

Affected Spring Products and Versions

Reactor Netty:

  • 1.1.0 - 1.1.12
  • 1.0.38 and earlier

Mitigation

Users of affected versions should upgrade to the corresponding fixed version.
Fix versionAvailability
1.1.13OSS
1.0.39OSS

No other steps are necessary.

As a temporary workaround, Reactor Netty 1.1.x and 1.0.x users can choose to disable Reactor Netty HTTP Server built-in integration with Micrometer.

Credit

The issue was identified and responsibly reported by James Yuzawa (https://github.com/yuzawa-san).

History

  • 2023-11-27: Initial vulnerability report published.

Get ahead

VMware offers training and certification to turbo-charge your progress.

Learn more

Get support

Tanzu Spring offers support and binaries for OpenJDK™, Spring, and Apache Tomcat® in one simple subscription.

Learn more

Upcoming events

Check out all the upcoming events in the Spring community.

View all