Inconsistent interpretation of HTTP requests in Netty - CVE-2019-20444

 

Inconsistent interpretation of HTTP requests in Netty - CVE-2019-20444

Published: February 14, 2020 / Updated: February 11, 2025


Vulnerability identifier: #VU25355
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-20444
CWE-ID: CWE-444
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform HTTP request smuggling attacks.

The vulnerability exists due to incorrect processing of HTTP headers without the colon within the HttpObjectDecoder.java file in Netty. A remote attacker can send a specially crafted HTTP request to the application and perform HTTP request smuggling attack.


Affected software

Netty
IBM Observability with Instana
Log Analysis
AMQ Clients
IBM Cloud Transformation Advisor
Autodesk Infraworks
IBM Watson Knowledge Catalog in Cloud Pak for Data
HPE Telco IP Mediation E-Media
IBM Spectrum Protect Plus
AMQ Streams
AMQ Broker
JBoss Enterprise Application Platform
Operations Analytics - Log Analysis
Security QRadar EDR
Dell Support Assist Enterprise
IBM Business Automation Manager Open Editions
Dell EMC PowerStore Family Operating System
IBM Cloud Pak for Watson AIOps
StreamSets Data Collector
IBM Sterling Order Management
Planning Analytics Local
netty (Debian package)
jctools
libnetty-3.9-java (Ubuntu package)
netty3
libnetty-java (Ubuntu package)
netty
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
RSA Authentication Manager
Ubuntu
openEuler
Fedora
Cloud Pak for Security (CP4S)
watsonx.data
Cloudera Data Platform Private Cloud Base for IBM
Red Hat Single Sign-On

How to mitigate CVE-2019-20444

Install updates from vendor's website.

Netty - update to 4.1.44
AMQ Streams - update to 1.4.0
Log Analysis - update to 1.3.8
Operations Analytics - Log Analysis - update to 1.3.8.4
AMQ Clients - update to 2.6.0
Planning Analytics Local - update to 2.0.1
IBM Cloud Transformation Advisor - update to 3.2.1
Security QRadar EDR - update to 3.12.15
Dell Support Assist Enterprise - update to 4.00.06.00
netty (Debian package) - update to 1:4.1.33-1+deb10u2
AMQ Broker - addressed in versions 7.4.3, 7.6
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.8.0
JBoss Enterprise Application Platform - update to 7.2.7
IBM Business Automation Manager Open Editions - update to 8.0.7
Autodesk Infraworks - addressed in versions 2021.2 Hotfix 9, 2023.1 Hotfix 1
Dell EMC PowerStore Family Operating System - update to 1.0.4.0.5.003
Cloud Pak for Security (CP4S) - update to 1.10.12.0
watsonx.data - addressed in versions 2.0.2, 2.0.3
jctools - update to 3.1.0-1.fc33
IBM Cloud Pak for Watson AIOps - update to 3.5
libnetty-3.9-java (Ubuntu package) - addressed in versions 3.9.0.Final-1ubuntu0.1, 3.9.9.Final-1+deb9u1build0.18.04.1
netty3 - update to 3.10.6-8
libnetty-java (Ubuntu package) - update to 1:4.1.7-4ubuntu0.1
netty - update to 4.1.51-1.fc33
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 4.8.0
StreamSets Data Collector - update to 7.0.0
Cloudera Data Platform Private Cloud Base for IBM - update to 7.1.7 SP2 Cumulative Hotfix 16
Red Hat Single Sign-On - update to 7.3.7
RSA Authentication Manager - update to 8.4 Patch 11
HPE Telco IP Mediation E-Media - update to 8.5.1
IBM Sterling Order Management - update to 10.0.0.29
IBM Spectrum Protect Plus - update to 10.1.14

External References

Related Security Bulletins