QID 980656
QID 980656: Java (maven) Security Update for io.netty:netty-all (GHSA-p979-4mfw-53vg)
Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-p979-4mfw-53vg for updates pertaining to this vulnerability.
Vendor References
- GHSA-p979-4mfw-53vg -
github.com/advisories/GHSA-p979-4mfw-53vg
CVEs related to QID 980656
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-p979-4mfw-53vg | io.netty:netty-all |
|