CVE-2019-20445HTTP Request Smuggling in Netty

Severity
9.1CRITICALNVD
OSV7.5
EPSS
2.8%
top 13.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 29
Latest updateOct 27

Description

HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 3.9 | Impact: 5.2

Affected Packages6 packages

NVDnetty/netty< 4.1.44
Debiannetty/netty< 1:4.1.45-1+3
Ubuntunetty/netty< 1:4.1.7-4ubuntu0.1
NVDapache/spark2.4.7, 2.4.8+1

Also affects: Debian Linux 10.0, 8.0, 9.0, Fedora 33, Ubuntu Linux 18.04

Patches

🔴Vulnerability Details

7
OSV
netty vulnerabilities2020-10-27
OSV
netty-3.9 vulnerabilities2020-10-22
OSV
netty-3.9 vulnerabilities2020-09-22
GHSA
HTTP Request Smuggling in Netty2020-02-21
OSV
HTTP Request Smuggling in Netty2020-02-21

📋Vendor Advisories

5
Ubuntu
Netty vulnerabilities2020-10-27
Ubuntu
Netty vulnerabilities2020-10-22
Ubuntu
Netty vulnerabilities2020-09-22
Red Hat
netty: HttpObjectDecoder.java allows Content-Length header to accompanied by second Content-Length header2020-01-29
Debian
CVE-2019-20445: netty - HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to ...2019

💬Community

2
Bugzilla
CVE-2019-20445 netty: HttpObjectDecoder.java allows Content-Length header to accompanied by second Content-Length header2020-02-05
Bugzilla
CVE-2019-20445 netty: HttpObjectDecoder.java allows Content-Length header to accompanied by second Content-Length header [fedora-all]2020-02-05
CVE-2019-20445 — HTTP Request Smuggling in Netty | cvebase