CVE-2019-20445 PUBLISHED

HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header.

EPSS 2.84% · 86.1th percentile

Risk Scores

EPSS Score
2.84%
86.1th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSnetty-3.90, 3.9.0.Final-1
Ubuntu:Pro:16.04:LTSnetty0, 1:3.2.6.Final-2, 1:4.0.32-1
Ubuntu:Pro:14.04:LTSnetty0, 1:3.2.6.Final-2
Ubuntu:18.04:LTSnetty-3.90, 3.9.9.Final-1
Ubuntu:18.04:LTSnetty0, 1:4.1.7-4

Timeline

References

Open in Interactive Console →