Loading vulnerability details...
An attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can bypass the restrictions.
io.netty.handler.ipfilter.IpSubnetFilterRule#compareTo(java.net.InetSocketAddress) method performs a bitwise AND between the incoming IP address and the configured networkAddress, instead of the subnetMask.
Access Control Bypass. Attacker can bypass IpSubnetFilter IPv6 access controls.
An attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can bypass the restrictions.
io.netty.handler.ipfilter.IpSubnetFilterRule#compareTo(java.net.InetSocketAddress) method performs a bitwise AND between the incoming IP address and the configured networkAddress, instead of the subnetMask.
Access Control Bypass. Attacker can bypass IpSubnetFilter IPv6 access controls.
This critical vulnerability poses an immediate and severe threat to system security. Exploitation could lead to complete system compromise, data breach, or denial of service. Immediate action is required.
Probability of exploitation in the next 30 days · more likely than 69.4% of all CVEs.
Apply security patches to version 4.2.15.Final, 4.1.135.Final immediately
Isolate affected systems from untrusted networks until patching is complete
Implement enhanced monitoring for exploitation attempts and unusual behavior