CVE Database
/

CVE-2020-7238

Back to search

CVE-2020-7238

Published: Jan 27, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked line) and a later Content-Length header. This issue exists because of an incomplete fix for CVE-2019-16869.

VendorProductVersions

n/a

n/a

affected
n/a

References

https://netty.io/news/
x_refsource_MISC
RHSA-2020:0497
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0601
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0606
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0605
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0567
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0806
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0811
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0804
vendor-advisory
x_refsource_REDHAT
RHSA-2020:0805
vendor-advisory
x_refsource_REDHAT
FEDORA-2020-66b5f85ccc
vendor-advisory
x_refsource_FEDORA
DSA-4885
vendor-advisory
x_refsource_DEBIAN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now