Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-10719

Опубликовано: 26 мая 2020
Источник: debian

Описание

A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
undertowfixed2.1.1-1package

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1828459

  • https://issues.redhat.com/browse/UNDERTOW-1708 (not public)

  • Most likely fixed by https://github.com/undertow-io/undertow/commit/bfc8fbd67f6b3dd96702b363f61cf805baf3c6cf

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 6 лет назад

A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling.

CVSS3: 6.5
redhat
больше 6 лет назад

A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling.

CVSS3: 6.5
nvd
больше 6 лет назад

A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling.

CVSS3: 6.5
github
больше 5 лет назад

HTTP Request Smuggling in Undertow