imPC@ndo IT

Tracker / CVE-2019-20445

CVE-2019-20445

Critical 9.1

HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header.

Affected products and versions

apache spark
canonical ubuntu_linux
debian debian_linux
fedoraproject fedora
netty netty · … → 4.1.44
redhat jboss_amq_clients
redhat jboss_enterprise_application_platform

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References