handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (infinite loop).
2017-04-13T14:59:01.823
2025-04-20T01:37:25.860
Deferred
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:C
10.0
6.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | netty | netty | < 4.0.37 | Yes |
| Application | netty | netty | < 4.1.1 | Yes |
| Application | redhat | jboss_data_grid | 7.1 | Yes |
| Application | redhat | jboss_middleware_text-only_advisories | 1.0 | Yes |
| Application | apache | cassandra | 3.11.4 | Yes |