Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-10719

Опубликовано: 26 мая 2020
Источник: debian
EPSS Низкий

Описание

A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
undertowfixed2.1.1-1package

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1828459

  • https://issues.redhat.com/browse/UNDERTOW-1708 (not public)

  • Most likely fixed by https://github.com/undertow-io/undertow/commit/bfc8fbd67f6b3dd96702b363f61cf805baf3c6cf

EPSS

Процентиль: 38%
0.00167
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 5 лет назад

A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling.

CVSS3: 6.5
redhat
почти 6 лет назад

A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling.

CVSS3: 6.5
nvd
больше 5 лет назад

A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling.

CVSS3: 6.5
github
почти 5 лет назад

HTTP Request Smuggling in Undertow

EPSS

Процентиль: 38%
0.00167
Низкий