CVE detail
CVE-2023-34062 — CVE-2023-34062
Published 2023-11-15 · Modified 2026-06-17 · Vendor pivotal · Product reactor_netty · Source nvd
HIGH
severity
CVSS-derived band
0.0112
EPSS probability
exploitation probability, 30d
63.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, a malicious user can send a request using a specially crafted URL that can lead to a directory traversal attack.
Specifically, an application is vulnerable if Reactor Netty HTTP Server is configured to serve static resources.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References