CVE-2020-10719
published 2020-05-26CVE-2020-10719: A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an…
PriorityP434medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
1.00%
59.1th percentile
A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | undertow | < undertow 2.1.1-1 (forky) | undertow 2.1.1-1 (forky) |
| netapp | oncommand_insight | < 7.3.13 | 7.3.13 |
| red_hat | undertow | — | — |
| redhat | fuse | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | undertow | < 2.1.1 | 2.1.1 |
| redhat | undertow | >= 0 < 2.1.1-1 | 2.1.1-1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
HTTP Request Smuggling in Undertow
osv·2021-04-30
CVE-2020-10719 [MEDIUM] HTTP Request Smuggling in Undertow
HTTP Request Smuggling in Undertow
A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling.
GHSA
HTTP Request Smuggling in Undertow
ghsa·2021-04-30
CVE-2020-10719 [MEDIUM] CWE-444 HTTP Request Smuggling in Undertow
HTTP Request Smuggling in Undertow
A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling.
OSV
CVE-2020-10719: A flaw was found in Undertow in versions before 2
osv·2020-05-26·CVSS 6.5
CVE-2020-10719 [MEDIUM] CVE-2020-10719: A flaw was found in Undertow in versions before 2
A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling.
Red Hat
undertow: invalid HTTP request with large chunk size
vendor_redhat·2020-05-06·CVSS 6.5
CVE-2020-10719 [MEDIUM] CWE-444 undertow: invalid HTTP request with large chunk size
undertow: invalid HTTP request with large chunk size
A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling.
A flaw was found in Undertow, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling.
Package: undertow (A-MQ Clients 2) - Not affected
Package: undertow (Red Hat Data Grid 8) - Not affected
Package: undertow (Red Hat Decision Manager 7) - Not affected
Package: undertow (Red Hat JBoss Data Grid 7) - Out of support scope
Package: undertow (Red Hat OpenShift Application Runtimes) - Affected
Package: undertow (Red Hat Process Automation
Debian
CVE-2020-10719: undertow - A flaw was found in Undertow in versions before 2.1.1.Final, regarding the proce...
vendor_debian·2020·CVSS 6.5
CVE-2020-10719 [MEDIUM] CVE-2020-10719: undertow - A flaw was found in Undertow in versions before 2.1.1.Final, regarding the proce...
A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling.
Scope: local
forky: resolved (fixed in 2.1.1-1)
sid: resolved (fixed in 2.1.1-1)
No detection rules found.
No public exploits indexed.
2020-05-26
Published