6.5
CVE-2020-10719
- EPSS 1.01%
- Veröffentlicht 26.05.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 04:55:55
- Erkennungen
A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Netapp ≫ Oncommand Insight Version < 7.3.13
Redhat ≫ Jboss Enterprise Application Platform Version - SwEdition text-only
Redhat ≫ Openshift Application Runtimes Version - SwEdition text-only
Redhat ≫ Single Sign-on Version - SwEdition text-only
Redhat ≫ Jboss Enterprise Application Platform Version 7.3
Redhat ≫ Jboss Enterprise Application Platform Version 7.4
Redhat ≫ Jboss Enterprise Application Platform Version 7.3
Redhat ≫ Jboss Enterprise Application Platform Version 7.4
Redhat ≫ Jboss Enterprise Application Platform Version 7.3
Redhat ≫ Jboss Enterprise Application Platform Version 7.2
Redhat ≫ Jboss Enterprise Application Platform Version 7.2
Redhat ≫ Jboss Enterprise Application Platform Version 7.2
Netapp ≫ Active Iq Unified Manager Version - SwPlatform linux
Netapp ≫ Active Iq Unified Manager Version - SwPlatform vmware_vsphere
Netapp ≫ Active Iq Unified Manager Version - SwPlatform windows
Netapp ≫ Oncommand Workflow Automation Version -
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.01% | 0.584 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.5 | 3.9 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
|
| NIST | 6.4 | 10 | 4.9 |
AV:N/AC:L/Au:N/C:P/I:P/A:N
|
| RedHat | 6.5 | 3.9 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
|
CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10719
https://security.netapp.com/advisory/ntap-20220210-0014/