HTTP Request Smuggling Vulnerability in Netty by Red Hat
CVE-2020-7238
7.5HIGH
Summary
Netty 4.1.43.Final is susceptible to HTTP Request Smuggling due to improper handling of whitespace in the Transfer-Encoding header. This flaw could lead to payload manipulation by an attacker, as it misinterprets a chunked transfer followed by a Content-Length header. This vulnerability arises from an incomplete patch addressing a prior issue, exposing systems to potential security risks.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved