io.netty:netty-handler-ssl-ocsp@4.2.9.Final

  • latest version

    4.2.16.Final

  • latest non vulnerable version

  • first published

    3 years ago

  • latest version published

    27 days ago

  • licenses detected

  • package registry

  • Direct Vulnerabilities

    Known vulnerabilities in the io.netty:netty-handler-ssl-ocsp package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • C
    Improper Check for Certificate Revocation

    io.netty:netty-handler-ssl-ocsp is a Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.

    Affected versions of this package are vulnerable to Improper Check for Certificate Revocation in the OcspServerCertificateValidator. An attacker can cause a revoked certificate to be accepted by replaying an expired OCSP response.

    How to fix Improper Check for Certificate Revocation?

    Upgrade io.netty:netty-handler-ssl-ocsp to version 4.1.136.Final, 4.2.16.Final or higher.

    [,4.1.136.Final)[4.2.0.Final,4.2.16.Final)
    • C
    Time-of-check Time-of-use (TOCTOU) Race Condition

    io.netty:netty-handler-ssl-ocsp is a Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.

    Affected versions of this package are vulnerable to Time-of-check Time-of-use (TOCTOU) Race Condition in the OcspServerCertificateValidator. An attacker can intercept sensitive application data or inject malicious responses by exploiting the window between the TLS handshake completion and the asynchronous OCSP validation result.

    How to fix Time-of-check Time-of-use (TOCTOU) Race Condition?

    Upgrade io.netty:netty-handler-ssl-ocsp to version 4.1.136.Final, 4.2.16.Final or higher.

    [,4.1.136.Final)[4.2.0.Final,4.2.16.Final)
    • C
    Improper Certificate Validation

    io.netty:netty-handler-ssl-ocsp is a Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients.

    Affected versions of this package are vulnerable to Improper Certificate Validation in the OcspClient.validateResponse. An attacker can bypass certificate revocation checks by replaying a legitimately signed OCSP response for a different certificate issued by the same certificate authority.

    How to fix Improper Certificate Validation?

    Upgrade io.netty:netty-handler-ssl-ocsp to version 4.1.136.Final, 4.2.16.Final or higher.

    [,4.1.136.Final)[4.2.0.Final,4.2.16.Final)