Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-10719

Опубликовано: 06 мая 2020
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling.

A flaw was found in Undertow, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Clients 2undertowNot affected
Red Hat Data Grid 8undertowNot affected
Red Hat Decision Manager 7undertowNot affected
Red Hat JBoss Data Grid 7undertowOut of support scope
Red Hat OpenShift Application RuntimesundertowAffected
Red Hat Process Automation 7undertowNot affected
EAP-CD 20 Tech PreviewundertowFixedRHSA-2020:358531.08.2020
Red Hat Fuse 7.9undertowFixedRHSA-2021:314011.08.2021
Red Hat JBoss EAP 7undertowFixedRHSA-2020:251510.06.2020
Red Hat JBoss EAP 7.2undertowFixedRHSA-2020:206111.05.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-444
https://bugzilla.redhat.com/show_bug.cgi?id=1828459undertow: invalid HTTP request with large chunk size

EPSS

Процентиль: 38%
0.00167
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 5 лет назад

A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling.

CVSS3: 6.5
nvd
больше 5 лет назад

A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling.

CVSS3: 6.5
debian
больше 5 лет назад

A flaw was found in Undertow in versions before 2.1.1.Final, regarding ...

CVSS3: 6.5
github
почти 5 лет назад

HTTP Request Smuggling in Undertow

EPSS

Процентиль: 38%
0.00167
Низкий

6.5 Medium

CVSS3

Уязвимость CVE-2020-10719