CVE-2024-29025
CVE-2024-29025 affects the Netty framework, potentially leading to resource exhaustion. This vulnerability allows an attacker to send a malicious HTTP post request with numerous small fields, overwhelming the server. The HttpPostRequestDecoder doesn't limit the number of form fields, leading to excessive data accumulation. Though the CVSS score is 5.3, the low SOCRadar Vulnerability Risk Score (SVRS) of 30 indicates a lower immediate threat level. Despite the lower SVRS, organizations using Netty should still apply the fix in version 4.1.108.Final to prevent a potential denial-of-service. While not currently considered a high-priority risk based on SVRS, addressing CWE-770 is crucial for long-term system stability.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.