GHSA-q4h9-7rxj-7gx2: Netty vulnerability included in redis lettuce
Note: i’m reporting this in this way purely because it’s private and i don’t want to broadcast vulnerabilities.
An unsafe reading of environment file could potentially cause a denial of service in Netty. When loaded on an Windows application, Netty attempts to load a file that does not exist. If an attacker creates such a large file, the Netty application crashes. This vulnerability is fixed in 4.1.115.
References
Detect and mitigate GHSA-q4h9-7rxj-7gx2 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →