Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Mageia 7: MGASA-2021-0123 Low: Undertow HTTP Request Smuggling Threat

mageia
Calendar Grey January 22, 2021
Dist Mageia Esm H88
Improvements for Undertow rectify a vulnerability allowing HTTP request smuggling exploits in Mageia 7 environments. Security measures detailed.
A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes

Summary

A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling (CVE-2020-10719).

References

- https://bugs.mageia.org/show_bug.cgi?id=28076

- https://security-tracker.debian.org/tracker/CVE-2020-10719

- https://www.cve.org/CVERecord?id=CVE-2020-10719

Resolution

SRPMS

- 7/core/undertow-1.4.0-2.1.mga7

Severity
low
Lowest
Low
Medium
High
Critical

Publication date: 22 Jan 2021
URL: https://advisories.mageia.org/MGASA-2021-0052.html
Type: security
CVE: CVE-2020-10719

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here