HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
DLA-2109-1 | netty security update |
![]() |
DLA-2110-1 | netty-3.9 security update |
![]() |
DLA-2364-1 | netty security update |
![]() |
DLA-2365-1 | netty-3.9 security update |
![]() |
DSA-4885-1 | netty security update |
![]() |
EUVD-2020-0308 | HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header. |
![]() |
GHSA-p2v9-g2qv-p635 | HTTP Request Smuggling in Netty |
![]() |
USN-4532-1 | Netty vulnerabilities |
![]() |
USN-4600-1 | Netty vulnerabilities |
![]() |
USN-4600-2 | Netty vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 26 Aug 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Redhat jboss Enterprise Application Platform Eus
|
|
CPEs | cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7 | |
Vendors & Products |
Redhat jboss Enterprise Application Platform Eus
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T02:39:10.039Z
Reserved: 2020-01-29T00:00:00
Link: CVE-2019-20445

No data.

Status : Modified
Published: 2020-01-29T21:15:11.110
Modified: 2024-11-21T04:38:30.087
Link: CVE-2019-20445


No data.