Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
AND |
|
History
30 Mar 2022, 14:21
Type | Values Removed | Values Added |
---|---|---|
References | (MLIST) https://lists.apache.org/thread.html/r73c400ab66d79821dec9e3472f0e2c048d528672bdb0f8bf44d7cb1f@%3Ccommits.cassandra.apache.org%3E - Mailing List, Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/r3225f7dfe6b8a37e800ecb8e31abd7ac6c4312dbd3223dd8139c37bb@%3Ccommits.cassandra.apache.org%3E - Mailing List, Third Party Advisory | |
CPE | cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.4:*:*:*:*:*:*:* |
24 Sep 2021, 16:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
27 May 2021, 16:22
Type | Values Removed | Values Added |
---|---|---|
References | (MLIST) https://lists.apache.org/thread.html/rc8d554aad889d12b140d9fd7d2d6fc2e8716e9792f6f4e4b2cdc2d05@%3Ccommits.cassandra.apache.org%3E - Mailing List, Third Party Advisory | |
References | (MLIST) https://lists.apache.org/thread.html/r131e572d003914843552fa45c4398b9903fb74144986e8b107c0a3a7@%3Ccommits.cassandra.apache.org%3E - Mailing List, Third Party Advisory |
26 May 2021, 17:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
26 May 2021, 08:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
Information
Published : 2019-09-26 16:15
Updated : 2024-02-04 20:39
NVD link : CVE-2019-16869
Mitre link : CVE-2019-16869
CVE.ORG link : CVE-2019-16869
JSON object : View
Products Affected
redhat
- jboss_enterprise_application_platform
- enterprise_linux
debian
- debian_linux
canonical
- ubuntu_linux
netty
- netty
CWE
CWE-444
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')