QID 981147

QID 981147: Java (maven) Security Update for com.typesafe.akka:akka-http-core_2.11 (GHSA-9qgc-p27w-3hjg)

The decodeRequest and decodeRequestWith directives in Lightbend Akka HTTP 10.1.x through 10.1.4 and 10.0.x through 10.0.13 allow remote attackers to cause a denial of service (memory consumption and daemon crash) via a ZIP bomb.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution
    Customers are advised to refer to GHSA-9qgc-p27w-3hjg for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 981147

    Software Advisories
    Advisory ID Software Component Link
    GHSA-9qgc-p27w-3hjg com.typesafe.akka:akka-http-core_2.11 URL Logo github.com/advisories/GHSA-9qgc-p27w-3hjg
    GHSA-9qgc-p27w-3hjg com.typesafe.akka:akka-http-core_2.12 URL Logo github.com/advisories/GHSA-9qgc-p27w-3hjg