Withdrawn Advisory: Netty vulnerability included in redis lettuce
Moderate severity
GitHub Reviewed
Published
Dec 2, 2024
to the GitHub Advisory Database
•
Updated Jan 16, 2025
Withdrawn
This advisory was withdrawn on Jan 16, 2025
Package
Affected versions
< 6.5.1.RELEASE
Patched versions
6.5.1.RELEASE
Description
Published to the GitHub Advisory Database
Dec 2, 2024
Reviewed
Dec 2, 2024
Withdrawn
Jan 16, 2025
Last updated
Jan 16, 2025
Withdrawn Advisory
This advisory has been withdrawn because users of Lettuce may independently exclude vulnerable versions of Netty from their dependencies, and those users should not receive alerts for CVE-2024-47535. This link is maintained to preserve external references.
Original Description
Summary
Note: i'm reporting this in this way purely because it's private and i don't want to broadcast vulnerabilities.
Details
https://github.com/redis/lettuce/blob/main/pom.xml#L67C9-L67C53 The netty version pinned here is currently
This version is vulnerable according to Snyk and is affecting one of our products:
Here is a link to the CVE
PoC
Complete instructions, including specific configuration details, to reproduce the vulnerability.
Not applicable
Impact
What kind of vulnerability is it? Who is impacted?
Denial of Service, affecting Windows users.
References