HTTP response splitting in Netty - CVE-2019-20445
Published: February 26, 2020 / Updated: February 11, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform HTTP splitting attacks.
The vulnerability exists due to software does not corrector process CRLF character sequences within the HttpObjectDecoder.java in Netty, which allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header. A remote attacker can send specially crafted request containing CRLF sequence and make the application to send a split HTTP response.
Successful exploitation of the vulnerability may allow an attacker perform cache poisoning attack.
Affected software
IBM Observability with Instana
Log Analysis
AMQ Clients
IBM Cloud Transformation Advisor
IBM Watson Knowledge Catalog in Cloud Pak for Data
HPE Telco IP Mediation E-Media
IBM Spectrum Protect Plus
AMQ Streams
AMQ Broker
JBoss Enterprise Application Platform
Planning Analytics Local
Security QRadar EDR
Dell Support Assist Enterprise
IBM Business Automation Manager Open Editions
Dell EMC PowerStore Family Operating System
IBM Cloud Pak for Watson AIOps
IBM Sterling Order Management
netty (Debian package)
jctools
libnetty-3.9-java (Ubuntu package)
netty3
libnetty-java (Ubuntu package)
netty
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
RSA Authentication Manager
Ubuntu
openEuler
Fedora
Cloud Pak for Security (CP4S)
watsonx.data
Cloudera Data Platform Private Cloud Base for IBM
Red Hat Single Sign-On
How to mitigate CVE-2019-20445
AMQ Streams - update to 1.4.0
Log Analysis - update to 1.3.8
Planning Analytics Local - update to 2.0.1
AMQ Clients - update to 2.6.0
IBM Cloud Transformation Advisor - update to 3.2.1
Security QRadar EDR - update to 3.12.15
Dell Support Assist Enterprise - update to 4.00.06.00
netty (Debian package) - update to 1:4.1.33-1+deb10u2
AMQ Broker - addressed in versions 7.4.3, 7.6
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.8.0
JBoss Enterprise Application Platform - update to 7.2.7
IBM Business Automation Manager Open Editions - update to 8.0.7
Dell EMC PowerStore Family Operating System - update to 1.0.4.0.5.003
Cloud Pak for Security (CP4S) - update to 1.10.12.0
watsonx.data - addressed in versions 2.0.2, 2.0.3
jctools - update to 3.1.0-1.fc33
IBM Cloud Pak for Watson AIOps - update to 3.5
libnetty-3.9-java (Ubuntu package) - addressed in versions 3.9.0.Final-1ubuntu0.1, 3.9.9.Final-1+deb9u1build0.18.04.1
netty3 - update to 3.10.6-8
libnetty-java (Ubuntu package) - update to 1:4.1.7-4ubuntu0.1
netty - update to 4.1.51-1.fc33
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 4.8.0
Cloudera Data Platform Private Cloud Base for IBM - update to 7.1.7 SP2 Cumulative Hotfix 16
Red Hat Single Sign-On - update to 7.3.7
RSA Authentication Manager - update to 8.4 Patch 11
HPE Telco IP Mediation E-Media - update to 8.5.1
IBM Sterling Order Management - update to 10.0.0.29
IBM Spectrum Protect Plus - update to 10.1.6.4
External References
- https://github.com/netty/netty/compare/netty-4.1.43.Final...netty-4.1.44.Final
- https://github.com/netty/netty/issues/9861
- https://lists.apache.org/thread.html/r310d2ce22304d5298ff87f10134f918c87919b452734f9841d95682d@%3Ccommits.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r36fcf538b28f2029e8b4f6b9a772f3b107913a78f09b095c5b153a62@%3Cissues.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r640eb9b3213058a963e18291f903fc1584e577f60035f941e32f760a@%3Cissues.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r70b1ff22ee80e8101805b9a473116dd33265709007d2deb6f8c80bf2@%3Ccommits.druid.apache.org%3E
- https://lists.apache.org/thread.html/r804895eedd72c9ec67898286eb185e04df852b0dd5fe53cf5b6138f9@%3Cissues.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r81700644754e66ffea465c869cb477de25f8041e21598e8818fc2c45@%3Cdev.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r96e08f929234e8ba1ef4a93a0fd2870f535a1f9ab628fabc46115986@%3Cdev.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r9b20cdac704cf9a583400350e2d5b576fa8417c18ddb961201676c60@%3Ccommits.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/ra2ace4bcb5cf487f72cbcbfa0f8cc08e755ec2b93d7e69f276148b08@%3Cissues.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/ra9fbfe7d4830ae675bf34c7c0f8c22fc8a4099f65706c1bc4f54c593@%3Cissues.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/rce71d33747010d32d31d90f5d737dae26291d96552f513a266c92fbb@%3Cnotifications.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/re45ee9256d3233c31d78e59ee59c7dc841c7fbd83d0769285b41e948@%3Ccommits.druid.apache.org%3E
- https://lists.apache.org/thread.html/rfb55f245b08d8a6ec0fb4dc159022227cd22de34c4419c2fbb18802b@%3Cnotifications.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/rff210a24f3a924829790e69eaefa84820902b7b31f17c3bf2def9114@%3Ccommits.druid.apache.org%3E
Related Security Bulletins
- Multiple vulnerabilities in Netty
- Red Hat AMQ Clients update for Netty
- Multiple vulnerabilities in JBoss Enterprise Application Platform
- Multiple vulnerabilities in Red Hat AMQ Streams
- Multiple vulnerabilities in Red Hat AMQ Broker
- Multiple vulnerabilities in Red Hat Process Automation Manager
- Debian update for netty
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in IBM Planning Analytics Local
- Multiple vulnerabilities in Dell EMC PowerStore Family Operating System
- Multiple Vulnerabilities in IBM CloudPak for Watson AIOPs
- Multiple vulnerabilities in IBM Sterling Order Management
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in IBM Observability with Instana (OnPrem)
- Multiple vulnerabilities in IBM Operations Analytics - Log Analysis
- Multiple vulnerabilities in IBM Watson Knowledge Catalog on-prem
- Multiple vulnerabilities in Dell Support Assist Enterprise
- openEuler 20.03 LTS SP4 update for netty3
- openEuler 22.03 LTS SP1 update for netty3
- openEuler 24.03 LTS update for netty3
- openEuler 22.03 LTS SP4 update for netty3
- Multiple vulnerabilities in IBM watsonx.data
- openEuler 22.03 LTS SP3 update for netty3
- IBM watsonx.data update for FasterXML jackson-databind
- Multiple vulnerabilities in IBM Spectrum Protect Plus
- Multiple vulnerabilities in IBM Security QRadar EDR
- Multiple vulnerabilities in HPE Telco IP Mediation Application
- Multiple vulnerabilities in IBM Business Automation Manager Open Editions
- Ubuntu update for netty-3.9
- Ubuntu update for netty-3.9
- Ubuntu update for netty
- Multiple vulnerabilities in Red Hat Single Sign-On 7.3
- Multiple vulnerabilities in AMQ Broker 7.4
- Fedora 33 update for jctools, netty
- RSA Authentication Manager update for third-party components
- Multiple vulnerabilities in Cloudera Data Platform Private Cloud Base with IBM (CDP)