Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-7238

Опубликовано: 27 янв. 2020
Источник: debian
EPSS Низкий

Описание

Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked line) and a later Content-Length header. This issue exists because of an incomplete fix for CVE-2019-16869.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
nettyfixed1:4.1.45-1package
netty-3.9removedpackage
netty-3.9not-affectedstretchpackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1796225

  • https://github.com/jdordonezn/CVE-2020-72381/issues/1

  • Issue exists because of incomplete fix for CVE-2019-16869.

  • https://github.com/netty/netty/issues/9861#issuecomment-582307539 (same fix as CVE-2019-20445)

EPSS

Процентиль: 71%
0.00685
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 5 лет назад

Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked line) and a later Content-Length header. This issue exists because of an incomplete fix for CVE-2019-16869.

CVSS3: 7.5
redhat
больше 5 лет назад

Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked line) and a later Content-Length header. This issue exists because of an incomplete fix for CVE-2019-16869.

CVSS3: 7.5
nvd
больше 5 лет назад

Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked line) and a later Content-Length header. This issue exists because of an incomplete fix for CVE-2019-16869.

CVSS3: 7.5
github
больше 5 лет назад

HTTP Request Smuggling in Netty

CVSS3: 7.5
redos
20 дней назад

Уязвимость netty

EPSS

Процентиль: 71%
0.00685
Низкий