Path traversal in Reactor Netty - CVE-2023-34062

 

Path traversal in Reactor Netty - CVE-2023-34062

Published: December 11, 2023


Vulnerability identifier: #VU84037
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-34062
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker can send a specially crafted HTTP request and read arbitrary files on the system.

Successful exploitation of the vulnerability requires that Reactor Netty HTTP Server is configured to serve static resources.


Affected software

Reactor Netty
IBM Security Guardium
IBM Disconnected Log Collector
Storage Copy Data Management
Cloud Pak for Network Automation
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
Dell Data Protection Central
Operational Decision Manager
IBM Observability with Instana

How to mitigate CVE-2023-34062

Install update from vendor's website.

Reactor Netty - addressed in versions 1.0.39, 1.1.13
IBM Disconnected Log Collector - update to 1.8.5
Storage Copy Data Management - update to 2.2.27.0
Cloud Pak for Network Automation - update to 2.6.5
DB2 Warehouse on Cloud Pak for Data - update to 4.8.2
DB2 on Cloud Pak for Data - update to 4.8.2
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 51, 8.11.0.1 Interim fix 27, 8.11.1 Interim fix 19, 8.12.0.1 Interim fix 1
Dell Data Protection Central - update to 19.11.0-2
IBM Observability with Instana - update to 266

External References

Related Security Bulletins