CyberRota Analysis
AI-GeneratedThe vulnerability affects Neethi's handling of remote policy references, allowing an attacker to exploit the time limitation on reads, potentially leading to a denial of service by keeping the fetch operation alive indefinitely. This can result in resource exhaustion as the calling thread remains tied up. Organizations utilizing Neethi should prioritize upgrading to version 3.2.4 to mitigate this risk.
Original NVD Description
When Neethi fetches a remote policy reference, it only limits the time per read, not the whole transfer, so a server that trickles bytes slowly can keep the fetch alive indefinitely and tie up the calling thread (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue.
Related CVEs
Other vulnerabilities affecting the same vendor(s)