CyberRota Analysis
AI-GeneratedThe vulnerability affects the Netty framework, specifically the `OcspClient` component, which fails to properly validate the `CertificateID` in OCSP responses, potentially allowing attackers to perform replay attacks and bypass revocation checks for unrelated certificates. Organizations using affected versions (4.2.0.Final to 4.2.15.Final and prior to 4.1.135.Final) should prioritize updating to versions 4.1.136.Final or 4.2.16.Final to mitigate the risk of unauthorized access due to this flaw. This is particularly critical for developers and operators of network applications relying on secure certificate validation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and prior to 4.1.135.Final, `OcspClient` does not validate that the `CertificateID` in an OCSP response matches the requested `CertificateID`, which can lead to replay attack. `OcspClient.validateResponse` accepts a legitimately signed `GOOD` status response for an unrelated certificate issued by the same CA, allowing bypass of revocation checks for another certificate. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
Related CVEs
Other vulnerabilities affecting the same vendor(s)