CyberSec.Space Logo
Back to CVE Browser

CVE-2019-20445

CRITICAL
9.1
CVSS Severity Score
EPSS Score0.1650%
EPSS Percentile15.88th
PublishedJan 29, 2020
Last ModifiedNov 21, 2024

Vulnerability Description

HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header.

Affected Platforms (CPE)

πŸ“¦
Netty

Netty

< 4.1.44
πŸ’»
Debian

Debian Linux

= 8.0
πŸ’»
Debian

Debian Linux

= 9.0
πŸ’»
Debian

Debian Linux

= 10.0
πŸ’»
Fedoraproject

Fedora

= 33
πŸ’»
Canonical

Ubuntu Linux

= 18.04
πŸ“¦
Redhat

Jboss Amq Clients

= 2
πŸ“¦
Redhat

Jboss Enterprise Application Platform

= 7.2
πŸ“¦
Redhat

Jboss Enterprise Application Platform

= 7.3
πŸ“¦
Apache

Spark

= 2.4.7
πŸ“¦
Apache

Spark

= 2.4.8

References & Advisories

Related Vulnerabilities