Vulnerability Description
HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an "invalid fold."
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netty | Netty | < 4.1.44 |
| Debian | Debian Linux | 8.0 |
| Fedoraproject | Fedora | 33 |
| Canonical | Ubuntu Linux | 18.04 |
| Redhat | Jboss Amq Clients | 2 |
| Redhat | Jboss Enterprise Application Platform | 7.2 |
| Redhat | Enterprise Linux | 6.0 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/errata/RHSA-2020:0497Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0567Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0601Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0605Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0606Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0804Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0805Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0806Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0811Third Party Advisory
- https://github.com/netty/netty/compare/netty-4.1.43.Final...netty-4.1.44.FinalPatchThird Party Advisory
- https://github.com/netty/netty/issues/9866ExploitIssue TrackingPatch
- https://github.com/poc-effectiveness/PoCAdaptation/tree/main/Adapted/CVE-2019-20
- https://lists.apache.org/thread.html/r059b042bca47be53ff8a51fd04d95eb01bb683f1af
- https://lists.apache.org/thread.html/r0aa8b28e76ec01c697b15e161e6797e88fc8d406ed
- https://lists.apache.org/thread.html/r0c3d49bfdbc62fd3915676433cc5899c5506d06da1
FAQ
What is CVE-2019-20444?
CVE-2019-20444 is a vulnerability with a CVSS score of 9.1 (CRITICAL). HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an "invalid...
How severe is CVE-2019-20444?
CVE-2019-20444 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-20444?
Check the references section above for vendor advisories and patch information. Affected products include: Netty Netty, Debian Debian Linux, Fedoraproject Fedora, Canonical Ubuntu Linux, Redhat Jboss Amq Clients.