SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-10719

This flaw allows an attacker to take advantage of HTTP request smuggling.

MEDIUM 6.5EPSS 1.00%

Does this matter?

Lower severity and a low EPSS score (1.00%). Track it; it rarely justifies an emergency change on its own.

Description

A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS
1.00% probability · 61th percentile
CISA KEV
Not listed
Weakness
CWE-444
Affected
redhat/undertow · netapp/oncommand insight · redhat/fuse · redhat/jboss enterprise application platform · redhat/openshift application runtimes · redhat/single sign-on · netapp/active iq unified manager · netapp/oncommand workflow automation
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.