org.apache.mina:mina-http@2.0.16 vulnerabilities

  • latest version

    2.2.4

  • latest non vulnerable version

  • first published

    12 years ago

  • latest version published

    27 days ago

  • licenses detected

  • package manager

  • Direct Vulnerabilities

    Known vulnerabilities in the org.apache.mina:mina-http package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Denial of Service (DoS)

    org.apache.mina:mina-http is an a network application framework which helps users develop high performance and high scalability network applications easily.

    Affected versions of this package are vulnerable to Denial of Service (DoS). Malformed HTTP requests may cause the HTTP Header decoder to loop indefinitely when there is more data than expected.

    How to fix Denial of Service (DoS)?

    Upgrade org.apache.mina:mina-http to version 2.1.5, 2.0.22 or higher.

    [2.1.0,2.1.5)[0,2.0.22)