GHSA-c438-6f6r-pg8w
Dashboard / Vulnerabilities / GHSA-c438-6f6r-pg8w
Summary: 4thline cling uPnP protocol issue can lead to denial of service
Details: An issue in the UPnP protocol in 4thline cling 2.0.0 through 2.1.2 allows remote attackers to cause a denial of service via an unchecked `CALLBACK` parameter in the request header. As of 2022, 4thline cling is no longer supported by the maintainers.
References: https://nvd.nist.gov/vuln/detail/CVE-2020-23622, https://github.com/4thline/cling/issues/253, https://github.com/4thline/cling, https://zh-cn.tenable.com/blog/cve-2020-12695-callstranger-vulnerability-in-universal-plug-and-play-upnp-puts-billions-of?tns_redirect=true
Affected packages
Package
Name: org.fourthline.cling:cling-core
Purl: pkg:maven/org.fourthline.cling/cling-core
Affected ranges
Type: ECOSYSTEM
Events:
