Skip to content

Conversation

@velo
Copy link
Member

@velo velo commented Nov 24, 2019

No description provided.

velo added 2 commits November 25, 2019 09:40
Vulnerable module: io.netty:netty-codec-http
Introduced through: io.reactivex:rxnetty-http@0.5.2 and io.reactivex:rxnetty-spectator-http@0.5.2
Exploit maturity: No known exploit
Vulnerable module: com.google.guava:guava
Introduced through: com.netflix.ribbon:ribbon-core@2.3.0 and com.netflix.ribbon:ribbon-loadbalancer@2.3.0
Exploit maturity: No known exploit

https://app.snyk.io/vuln/SNYK-JAVA-COMGOOGLEGUAVA-32236
@velo velo merged commit 2087d4b into OpenFeign:master Nov 24, 2019
@velo velo deleted the vunerabilities branch November 24, 2019 20:59
velo added a commit that referenced this pull request Oct 7, 2024
* Fix for HTTP Request Smuggling
Vulnerable module: io.netty:netty-codec-http
Introduced through: io.reactivex:rxnetty-http@0.5.2 and io.reactivex:rxnetty-spectator-http@0.5.2
Exploit maturity: No known exploit

* Fix for Deserialization of Untrusted Data
Vulnerable module: com.google.guava:guava
Introduced through: com.netflix.ribbon:ribbon-core@2.3.0 and com.netflix.ribbon:ribbon-loadbalancer@2.3.0
Exploit maturity: No known exploit

https://app.snyk.io/vuln/SNYK-JAVA-COMGOOGLEGUAVA-32236
velo added a commit that referenced this pull request Oct 8, 2024
* Fix for HTTP Request Smuggling
Vulnerable module: io.netty:netty-codec-http
Introduced through: io.reactivex:rxnetty-http@0.5.2 and io.reactivex:rxnetty-spectator-http@0.5.2
Exploit maturity: No known exploit

* Fix for Deserialization of Untrusted Data
Vulnerable module: com.google.guava:guava
Introduced through: com.netflix.ribbon:ribbon-core@2.3.0 and com.netflix.ribbon:ribbon-loadbalancer@2.3.0
Exploit maturity: No known exploit

https://app.snyk.io/vuln/SNYK-JAVA-COMGOOGLEGUAVA-32236
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant