Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ff2w-cq2g-wv5f

Опубликовано: 21 фев. 2020
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

HTTP Request Smuggling in Netty

Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked line) and a later Content-Length header. This issue exists because of an incomplete fix for CVE-2019-16869.

Пакеты

Наименование

io.netty:netty-handler

maven
Затронутые версииВерсия исправления

>= 4.1.43, <= 4.1.44

4.1.45

EPSS

Процентиль: 82%
0.01687
Низкий

7.5 High

CVSS3

Дефекты

CWE-444

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 6 лет назад

Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked line) and a later Content-Length header. This issue exists because of an incomplete fix for CVE-2019-16869.

CVSS3: 7.5
redhat
почти 6 лет назад

Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked line) and a later Content-Length header. This issue exists because of an incomplete fix for CVE-2019-16869.

CVSS3: 7.5
nvd
почти 6 лет назад

Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked line) and a later Content-Length header. This issue exists because of an incomplete fix for CVE-2019-16869.

CVSS3: 7.5
debian
почти 6 лет назад

Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles ...

CVSS3: 7.5
redos
5 месяцев назад

Уязвимость netty

EPSS

Процентиль: 82%
0.01687
Низкий

7.5 High

CVSS3

Дефекты

CWE-444