VulnerabilityModified
CVE-2020-10719
This flaw allows an attacker to take advantage of HTTP request smuggling.
MEDIUM 6.5EPSS 1.00%
Does this matter?
Lower severity and a low EPSS score (1.00%). Track it; it rarely justifies an emergency change on its own.
Description
A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 1.00% probability · 61th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-444
- Affected
- redhat/undertow · netapp/oncommand insight · redhat/fuse · redhat/jboss enterprise application platform · redhat/openshift application runtimes · redhat/single sign-on · netapp/active iq unified manager · netapp/oncommand workflow automation
- Source
- secalert@redhat.com
References
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10719Issue Tracking, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20220210-0014/Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10719Issue Tracking, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20220210-0014/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.