Lucene search

K
osvGoogleOSV:USN-4532-1
HistorySep 22, 2020 - 4:15 p.m.

netty-3.9 vulnerabilities

2020-09-2216:15:05
Google
osv.dev
4

7.5 High

AI Score

Confidence

Low

0.012 Low

EPSS

Percentile

85.6%

It was discovered that Netty incorrectly handled certain HTTP headers.
By sending an HTTP header with whitespace before the colon, a remote
attacker could possibly use this issue to perform an HTTP request
smuggling attack. (CVE-2019-16869)

It was discovered that Netty incorrectly handled certain HTTP headers.
By sending an HTTP header that lacks a colon, a remote attacker could
possibly use this issue to perform an HTTP request smuggling attack.
(CVE-2019-20444)

It was discovered that Netty incorrectly handled certain HTTP headers.
By sending a Content-Length header accompanied by a second Content-Length
header, or by a Transfer-Encoding header, a remote attacker could possibly
use this issue to perform an HTTP request smuggling attack.
(CVE-2019-20445)