Description
Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked line) and a later Content-Length header. This issue exists because of an incomplete fix for CVE-2019-16869.
Published: 2020-01-27
Score: 7.5 High
EPSS: 1.5% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-2109-1 netty security update
Debian DLA Debian DLA DLA-2110-1 netty-3.9 security update
Debian DLA Debian DLA DLA-2364-1 netty security update
Debian DSA Debian DSA DSA-4885-1 netty security update
EUVD EUVD EUVD-2020-0303 Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked line) and a later Content-Length header. This issue exists because of an incomplete fix for CVE-2019-16869.
Github GHSA Github GHSA GHSA-ff2w-cq2g-wv5f HTTP Request Smuggling in Netty
Ubuntu USN Ubuntu USN USN-4600-1 Netty vulnerabilities
History

Mon, 25 Nov 2024 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat jboss Enterprise Application Platform Eus
CPEs cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7
Vendors & Products Redhat jboss Enterprise Application Platform Eus

Subscriptions

Debian Debian Linux
Fedoraproject Fedora
Netty Netty
Redhat A Mq Clients Amq Broker Amq Online Amq Streams Jboss Data Grid Jboss Enterprise Application Platform Jboss Enterprise Application Platform Cd Jboss Enterprise Application Platform Eus Jboss Enterprise Application Platform Text-only Advisories Jboss Enterprise Bpms Platform Jboss Enterprise Brms Platform Jboss Fuse Jboss Single Sign On Openshift Application Runtimes Openshift Application Runtimes Text-only Advisories Satellite Satellite Capsule
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T09:25:48.271Z

Reserved: 2020-01-20T00:00:00.000Z

Link: CVE-2020-7238

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-01-27T17:15:12.277

Modified: 2024-11-21T05:36:53.793

Link: CVE-2020-7238

cve-icon Redhat

Severity : Important

Publid Date: 2020-01-26T00:00:00Z

Links: CVE-2020-7238 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses