CVE-2023-34062
Executive Summary
CVE-2023-34062 enables directory traversal on applications using Reactor Netty HTTP Server (v1.1.x <1.1.13 or v1.0.x <1.0.39) when configured to serve static resources. A malicious user can craft a URL to access files outside the intended directory, potentially exposing sensitive data or facilitating further attacks. The vulnerability is not yet listed in CISA KEV.
Authoritative CVE Metadata - CVSS Base Score: 7.5 (HIGH) - Published: 2023-11-15T10:15:07.277 - Last Modified: 2026-09-04T18:59:12.370
Original Description: In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, a malicious user can send a request using a specially crafted URL that can lead to a directory traversal attack.
Specifically, an application is vulnerable if Reactor Netty HTTP Server is configured to serve static resources.
"As we are liberated from our own fear, our presence automatically liberates others."
— Nelson Mandela