Micrometer
- >= 1.16.0, <= 1.16.5
- >= 1.15.0, <= 1.15.11
- >= 1.14.0, <= 1.14.15
- >= 1.13.0, <= 1.13.18
- >= 1.9.0, <= 1.9.17
A denial-of-service vulnerability has been identified in Micrometer's HTTP server instrumentations. Affected users can send specially crafted HTTP requests that lead to a DoS condition. This issue arises in applications using vulnerable versions of 'micrometer-core', 'micrometer-jetty11', or 'micrometer-jetty12', when the HTTP server instrumentations from these artifacts are active and metrics are being recorded.
Exploitation of this vulnerability can cause a denial-of-service condition, disrupting the normal operation of the affected application by overwhelming the server or causing it to become unresponsive.
Users should upgrade to Micrometer versions 1.16.6, 1.15.12, 1.14.16 (Enterprise Support Only), 1.13.19 (Enterprise Support Only) or 1.9.18 (Enterprise Support Only).
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.