← Vulnerability feed

Vulnerability record · CVE-2024-23639 · published 9 February 2024

CVE-2024-23639: Objectcomputing micronaut vulnerability

Objectcomputing · Micronaut

Micronaut Framework is a modern, JVM-based, full stack Java framework designed for building modular, easily testable JVM applications with support for Java, Kotlin and the Groovy language. Enabled but unsecured management endpoints are susceptible to drive-by localhost attacks. While not typical of a production application, these attacks may have more impact on a development environment where such endpoints may be flipped on without much thought. A malicious/compromised website can make HTTP requests to `localhost`. Normally, such requests would trigger a CORS preflight check which would prevent the request; however, some requests are "simple" and do not require a preflight check. These endpoints, if enabled and not secured, are vulnerable to being triggered. Production environments typically disable unused endpoints and secure/restrict access to needed endpoints. A more likely victim is the developer in their local development host, who has enabled endpoints without security for the sake of easing development. This issue has been addressed in version 3.8.3. Users are advised to upgrade.

7.8 CVSS 3.1 High EPSS 0.26% · top 83.9% CWE-15 · CWE-15CWE-610 · CWE-610
7.8CVSS 3.1 base score
0.26%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Micronaut Framework is a modern, JVM-based, full stack Java framework designed for building modular, easily testable JVM applications with support for Java, Kotlin and the Groovy language. Enabled but unsecured management endpoints are susceptible to drive-by localhost attacks. While not typical of a production application, these attacks may have more impact on a development environment where such endpoints may be flipped on without much thought. A malicious/compromised website can make HTTP requests to `localhost`. Normally, such requests would trigger a CORS preflight check which would prevent the request; however, some requests are "simple" and do not require a preflight check. These endpoints, if enabled and not secured, are vulnerable to being triggered. Production environments typically disable unused endpoints and secure/restrict access to needed endpoints. A more likely victim is the developer in their local development host, who has enabled endpoints without security for the sake of easing development. This issue has been addressed in version 3.8.3. Users are advised to upgrade.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-23639 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-7611Objectcomputing micronaut http request smuggling vulnerabilityAll versions of io.micronaut:micronaut-http-client before 1.2.11 and all versions from 1.3.0 before 1.3.2 are vulnerable to HTTP Request Header Injec…EPSS 1.8%8.2CVE-2026-33013Objectcomputing micronaut vulnerabilityMicronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. Versions prior to both …EPSS 0.78%7.5CVE-2026-33012Objectcomputing micronaut allocation without limits vulnerabilityMicronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. Versions 4.7.0 through …EPSS 0.75%7.5CVE-2021-32769Objectcomputing micronaut path traversal vulnerabilityMicronaut is a JVM-based, full stack Java framework designed for building JVM applications. A path traversal vulnerability exists in versions prior t…EPSS 1.7%5.3CVE-2022-21700Objectcomputing micronaut uncontrolled resource consumption vulnerabilityMicronaut is a JVM-based, full stack Java framework designed for building JVM web applications with support for Java, Kotlin and the Groovy language.…EPSS 1.2%8.8CVE-2009-1537Microsoft DirectShow QuickTime Parser NULL Byte Overwrite RCEThe QuickTime Movie Parser Filter in quartz.dll (DirectShow, DirectX 7.0 through 9.0c) contains an unspecified NULL byte overwrite flaw. A crafted Qu…KEVEPSS 51%analysed10.0CVE-2025-47812Wing FTP Server null byte handling leads to Lua code injection RCEWing FTP Server before 7.4.4 mishandles '\0' bytes in its user and admin web interfaces, allowing injection of arbitrary Lua code into user session f…KEVEPSS 93%analysed

Source: NIST National Vulnerability Database (record CVE-2024-23639), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.