ZeroHour

CVE-2020-10719

CVSS 3.1
6.5 medium
EPSS
1%p61
Published
()
Modified
Description

A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling.

Vendors
redhatnetapp
Products
undertow, oncommand insight, fuse, jboss enterprise application platform, openshift application runtimes, single sign-on, active iq unified manager, oncommand workflow automation
Weakness
CWE-444
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.