Skip to content

CVE-2019-20444 @ Maven-io.netty:netty-codec-http-4.1.42.Final #30

@ytang1-godaddy

Description

@ytang1-godaddy

Vulnerable Package issue exists @ Maven-io.netty:netty-codec-http-4.1.42.Final in branch master

HttpObjectDecoder.java in Netty before 4.1.44 and 5.x up to 5.0.0.Alpha2 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an "invalid fold."

Namespace: ytang1-godaddy
Repository: aws-cdk-examples
Repository Url: https://github.com/ytang1-godaddy/aws-cdk-examples
CxAST-Project: ytang1-godaddy/aws-cdk-examples
CxAST platform scan: 9299eec0-db6d-4aaf-a84e-cae2611689d7
Branch: master
Application: aws-cdk-examples
Severity: HIGH
State: NOT_IGNORED
Status: RECURRENT
CWE: CWE-444


Additional Info
Attack vector: NETWORK
Attack complexity: LOW
Confidentiality impact: HIGH
Availability impact: NONE
Remediation Upgrade Recommendation: 4.1.71.Final


References
Issue
Pull request
Commit

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions