Vulnerability Description
HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netty | Netty | < 4.1.44 |
| Debian | Debian Linux | 8.0 |
| Fedoraproject | Fedora | 33 |
| Canonical | Ubuntu Linux | 18.04 |
| Redhat | Jboss Amq Clients | 2 |
| Redhat | Jboss Enterprise Application Platform | 7.2 |
| Redhat | Enterprise Linux | 6.0 |
| Apache | Spark | 2.4.7 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/errata/RHSA-2020:0497Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0567Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0601Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0605Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0606Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0804Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0805Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0806Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0811Third Party Advisory
- https://github.com/netty/netty/compare/netty-4.1.43.Final...netty-4.1.44.FinalPatchRelease NotesThird Party Advisory
- https://github.com/netty/netty/issues/9861ExploitIssue TrackingPatch
- https://lists.apache.org/thread.html/r030beff88aeb6d7a2d6cd21342bd18686153ce6e26
- https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab
- https://lists.apache.org/thread.html/r1fcccf8bdb3531c28bc9aa605a6a1bea7e68cef6fc
- https://lists.apache.org/thread.html/r205937c85817a911b0c72655c2377e7a2c9322d6ef
FAQ
What is CVE-2019-20445?
CVE-2019-20445 is a vulnerability with a CVSS score of 9.1 (CRITICAL). HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header.
How severe is CVE-2019-20445?
CVE-2019-20445 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-20445?
Check the references section above for vendor advisories and patch information. Affected products include: Netty Netty, Debian Debian Linux, Fedoraproject Fedora, Canonical Ubuntu Linux, Redhat Jboss Amq Clients.