XNIO `notifyReadClosed` method logging message to unexpected end
High severity
GitHub Reviewed
Published
Aug 27, 2022
to the GitHub Advisory Database
•
Updated Jan 31, 2023
Description
Published by the National Vulnerability Database
Aug 26, 2022
Published to the GitHub Advisory Database
Aug 27, 2022
Reviewed
Sep 2, 2022
Last updated
Jan 31, 2023
A flaw was found in XNIO, specifically in the
notifyReadClosed
method. The issue revealed this method was logging a message to another expected end. This flaw allows an attacker to send flawed requests to a server, possibly causing log contention-related performance concerns or an unwanted disk fill-up. A fix for this issue is available on the3.x
branch of the repository.References