Lucene search

K
f5F5F5:K14752415
HistoryJul 13, 2020 - 12:00 a.m.

K14752415 : Netty vulnerability CVE-2019-20444

2020-07-1300:00:00
my.f5.com
6

6.4 Medium

AI Score

Confidence

Low

0.009 Low

EPSS

Percentile

82.4%

Security Advisory Description

HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an “invalid fold.”(CVE-2019-20444)

Impact

This vulnerability may result in HTTP request smuggling. When malformed or abnormal HTTP requests are interpreted, the system may interpret them inconsistently, allowing the attacker to ‘smuggle’ a request to one device while the other device is unaware of it.