QID 981502
QID 981502: Java (maven) Security Update for io.netty:netty-handler (GHSA-cqqj-4p63-rrmm)
HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an "invalid fold."
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-cqqj-4p63-rrmm for updates pertaining to this vulnerability.
Vendor References
- GHSA-cqqj-4p63-rrmm -
github.com/advisories/GHSA-cqqj-4p63-rrmm
CVEs related to QID 981502
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-cqqj-4p63-rrmm | io.netty:netty-handler |
|