CVE-2019-20445
CRITICAL
9.1
CVSS Severity Score
Vulnerability Description
HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header.
Affected Platforms (CPE)
π¦
Netty
Netty
< 4.1.44π»
Debian
Debian Linux
= 8.0π»
Debian
Debian Linux
= 9.0π»
Debian
Debian Linux
= 10.0π»
Fedoraproject
Fedora
= 33π»
Canonical
Ubuntu Linux
= 18.04π¦
Redhat
Jboss Amq Clients
= 2π¦
Redhat
Jboss Enterprise Application Platform
= 7.2π¦
Redhat
Jboss Enterprise Application Platform
= 7.3π¦
Apache
Spark
= 2.4.7π¦
Apache
