Overview
About vulnerability
In specific scenarios involving multiple clients with different DNS resolver configurations, Reactor Netty may incorrectly reuse a previously configured DNS resolver. In order for this to happen, the application must dynamically create multiple clients (such asHttpClient or TcpClient)
that rely on different custom configuration. This can lead to traffic being routed to unintended destinations.
Details
- Affected product:
- Netty , Spring , azure-sdk-for-java , azure-search-documents , rsocket-java , tika
- Affected packages:
- Spring Integration @ 5.5.19 (+2676 more)