-
Task
-
Resolution: Done
-
Major
-
None
-
None
Remediation
Upgrade io.netty:netty-all to version 4.1.42 or later. For example:
<dependency> <groupId>io.netty</groupId> <artifactId>netty-all</artifactId> <version>[4.1.42,)</version> </dependency>
CVE-2019-16869
moderate severity
Vulnerable versions: < 4.1.42
Patched version: 4.1.42
Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling.