{"id":"GHSA-c438-6f6r-pg8w","summary":"4thline cling uPnP protocol issue can lead to denial of service","details":"An issue in the UPnP protocol in 4thline cling 2.0.0 through 2.1.2 allows remote attackers to cause a denial of service via an unchecked `CALLBACK` parameter in the request header. As of 2022, 4thline cling is no longer supported by the maintainers.","aliases":["CVE-2020-23622"],"modified":"2023-11-01T04:52:34.033317Z","published":"2022-08-16T00:00:22Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2022-08-18T19:18:55Z","nvd_published_at":"2022-08-15T20:15:00Z","cwe_ids":["CWE-918"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-23622"},{"type":"WEB","url":"https://github.com/4thline/cling/issues/253"},{"type":"PACKAGE","url":"https://github.com/4thline/cling"},{"type":"WEB","url":"https://zh-cn.tenable.com/blog/cve-2020-12695-callstranger-vulnerability-in-universal-plug-and-play-upnp-puts-billions-of?tns_redirect=true"}],"affected":[{"package":{"name":"org.fourthline.cling:cling-core","ecosystem":"Maven","purl":"pkg:maven/org.fourthline.cling/cling-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0"},{"last_affected":"2.1.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/08/GHSA-c438-6f6r-pg8w/GHSA-c438-6f6r-pg8w.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}