ZeroHour

CVE-2019-20444

PoC
CVSS 3.1
9.1 critical
EPSS
9%p95
Published
()
Modified
Description

HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an "invalid fold."

Vendors
nettydebianfedoraprojectcanonicalredhat
Products
netty, debian linux, fedora, ubuntu linux, jboss amq clients, jboss enterprise application platform
Weakness
CWE-444
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.