CVE-2019-20445

Source
https://cve.org/CVERecord?id=CVE-2019-20445
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-20445.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-20445
Aliases
Downstream
Published
2020-01-29T21:15:11.110Z
Modified
2026-04-02T03:08:26.013576Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
[none]
Details

HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header.

References

Affected packages

Git / github.com/apache/spark

Affected ranges

Type
GIT
Repo
https://github.com/apache/spark
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.4.7"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.4.8"
        }
    ]
}
Type
GIT
Repo
https://github.com/netty/netty
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "4.1.44"
        }
    ]
}

Affected versions

0.*
0.3-scala-2.8
0.3-scala-2.9
2.*
2.0.0-preview
alpha-0.*
alpha-0.1
alpha-0.2
netty-3.*
netty-3.10.0.Final
netty-3.10.1.Final
netty-3.10.2.Final
netty-3.10.3.Final
netty-3.10.4.Final
netty-3.10.5.Final
netty-3.10.6.Final
netty-3.2.10.Final
netty-3.2.4.Final
netty-3.2.5.Final
netty-3.2.6.Final
netty-3.2.7.Final
netty-3.2.8.Final
netty-3.2.9.Final
netty-3.3.0.Final
netty-3.3.1.Final
netty-3.4.0.Alpha1
netty-3.4.0.Alpha2
netty-3.4.0.Beta1
netty-3.4.0.Final
netty-3.4.1.Final
netty-3.4.2.Final
netty-3.4.3.Final
netty-3.4.4.Final
netty-3.4.5.Final
netty-3.4.6.Final
netty-3.5.0.Beta1
netty-3.5.0.Final
netty-3.5.1.Final
netty-3.5.10.Final
netty-3.5.11.Final
netty-3.5.12.Final
netty-3.5.13.Final
netty-3.5.2.Final
netty-3.5.3.Final
netty-3.5.4.Final
netty-3.5.5.Final
netty-3.5.6.Final
netty-3.5.7.Final
netty-3.5.8.Final
netty-3.5.9.Final
netty-3.6.0.Beta1
netty-3.6.0.Final
netty-3.6.1.Final
netty-3.6.10.Final
netty-3.6.2.Final
netty-3.6.3.Final
netty-3.6.4.Final
netty-3.6.5.Final
netty-3.6.6.Final
netty-3.6.7.Final
netty-3.6.8.Final
netty-3.6.9.Final
netty-3.7.0.Final
netty-3.7.1.Final
netty-3.8.0.Final
netty-3.8.1.Final
netty-3.8.2.Final
netty-3.8.3.Final
netty-3.9.0.Final
netty-3.9.1.1.Final
netty-3.9.1.Final
netty-3.9.2.Final
netty-3.9.3.Final
netty-3.9.4.Final
netty-3.9.5.Final
netty-3.9.6.Final
netty-3.9.7.Final
netty-3.9.8.Final
netty-3.9.9.Final
netty-4.*
netty-4.0.0.Alpha1
netty-4.0.0.Alpha2
netty-4.0.0.Alpha3
netty-4.0.0.Alpha4
netty-4.0.0.Alpha5
netty-4.0.0.Alpha6
netty-4.0.0.Alpha7
netty-4.0.0.Alpha8
netty-4.0.0.Beta1
netty-4.0.0.Beta2
netty-4.0.0.Beta3
netty-4.0.0.CR1
netty-4.0.0.CR2
netty-4.0.0.CR3
netty-4.0.0.CR4
netty-4.0.0.CR5
netty-4.0.0.CR6
netty-4.0.0.CR7
netty-4.0.0.CR8
netty-4.0.0.CR9
netty-4.0.0.Final
netty-4.0.1.Final
netty-4.0.10.Final
netty-4.0.11.Final
netty-4.0.12.Final
netty-4.0.13.Final
netty-4.0.14.Beta1
netty-4.0.14.Final
netty-4.0.15.Final
netty-4.0.16.Final
netty-4.0.17.Final
netty-4.0.18.Final
netty-4.0.19.Final
netty-4.0.2.Final
netty-4.0.20.Final
netty-4.0.21.Final
netty-4.0.22.Final
netty-4.0.23.Final
netty-4.0.24.Final
netty-4.0.25.Final
netty-4.0.26.Final
netty-4.0.27.Final
netty-4.0.28.Final
netty-4.0.29.Final
netty-4.0.3.Final
netty-4.0.30.Final
netty-4.0.31.Final
netty-4.0.32.Final
netty-4.0.33.Final
netty-4.0.34.Final
netty-4.0.35.Final
netty-4.0.36.Final
netty-4.0.37.Final
netty-4.0.38.Final
netty-4.0.39.Final
netty-4.0.4.Final
netty-4.0.40.Final
netty-4.0.41.Final
netty-4.0.42.Final
netty-4.0.43.Final
netty-4.0.44.Final
netty-4.0.45.Final
netty-4.0.46.Final
netty-4.0.47.Final
netty-4.0.48.Final
netty-4.0.49.Final
netty-4.0.5.Final
netty-4.0.50.Final
netty-4.0.51.Final
netty-4.0.52.Final
netty-4.0.53.Final
netty-4.0.54.Final
netty-4.0.55.Final
netty-4.0.56.Final
netty-4.0.6.Final
netty-4.0.7.Final
netty-4.0.8.Final
netty-4.0.9.Final
netty-4.1.0.Beta1
netty-4.1.0.Beta2
netty-4.1.0.Beta3
netty-4.1.0.Beta4
netty-4.1.0.Beta5
netty-4.1.0.Beta6
netty-4.1.0.Beta7
netty-4.1.0.Beta8
netty-4.1.0.CR1
netty-4.1.0.CR2
netty-4.1.0.CR3
netty-4.1.0.CR4
netty-4.1.0.CR5
netty-4.1.0.CR6
netty-4.1.0.CR7
netty-4.1.0.Final
netty-4.1.1.Final
netty-4.1.10.Final
netty-4.1.11.Final
netty-4.1.12.Final
netty-4.1.13.Final
netty-4.1.14.Final
netty-4.1.15.Final
netty-4.1.16.Final
netty-4.1.17.Final
netty-4.1.18.Final
netty-4.1.19.Final
netty-4.1.2.Final
netty-4.1.20.Final
netty-4.1.21.Final
netty-4.1.22.Final
netty-4.1.23.Final
netty-4.1.24.Final
netty-4.1.25.Final
netty-4.1.26.Final
netty-4.1.27.Final
netty-4.1.28.Final
netty-4.1.29.Final
netty-4.1.3.Final
netty-4.1.30.Final
netty-4.1.31.Final
netty-4.1.32.Final
netty-4.1.33.Final
netty-4.1.34.Final
netty-4.1.35.Final
netty-4.1.36.Final
netty-4.1.37.Final
netty-4.1.38.Final
netty-4.1.39.Final
netty-4.1.4.Final
netty-4.1.40.Final
netty-4.1.41.Final
netty-4.1.42.Final
netty-4.1.43.Final
netty-4.1.5.Final
netty-4.1.6.Final
netty-4.1.7.Final
netty-4.1.8.Final
netty-4.1.9.Final
netty-5.*
netty-5.0.0.Alpha1
netty-5.0.0.Alpha2
netty-5.0.0.Alpha3
netty-5.0.0.Alpha4
netty-5.0.0.Alpha5
Other
netty-tag
v0.*
v0.5.0
v0.5.1
v0.5.2
v0.6.0
v0.6.0-yarn
v0.6.1
v0.6.2
v0.7.0
v0.7.0-bizo-1
v0.7.1
v0.7.2
v0.8.0-incubating
v0.8.1-incubating
v0.9.0-incubating
v0.9.1
v0.9.2
v1.*
v1.0.0
v1.0.1
v1.0.2
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.2.2
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.5.0-rc1
v1.5.0-rc2
v1.5.0-rc3
v1.5.1
v1.5.2
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v2.*
v2.0.0
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.2-rc1
v2.1.2-rc2
v2.1.2-rc3
v2.1.2-rc4
v2.1.3
v2.1.3-rc1
v2.1.3-rc2
v2.2.0
v2.2.1
v2.2.1-rc1
v2.2.1-rc2
v2.2.2
v2.2.2-rc1
v2.2.2-rc2
v2.2.3
v2.2.3-rc1
v2.3.0
v2.3.0-rc1
v2.3.0-rc2
v2.3.0-rc3
v2.3.0-rc4
v2.3.1
v2.3.1-rc1
v2.3.1-rc2
v2.3.1-rc3
v2.3.1-rc4
v2.3.2
v2.3.2-rc1
v2.3.2-rc2
v2.3.2-rc3
v2.3.2-rc4
v2.3.2-rc5
v2.3.2-rc6
v2.3.3
v2.3.3-rc1
v2.3.3-rc2
v2.3.4
v2.3.4-rc1
v2.4.0
v2.4.0-rc1
v2.4.0-rc2
v2.4.0-rc3
v2.4.0-rc4
v2.4.0-rc5
v2.4.1
v2.4.1-rc1
v2.4.1-rc2
v2.4.1-rc3
v2.4.1-rc4
v2.4.1-rc5
v2.4.1-rc6
v2.4.1-rc7
v2.4.1-rc8
v2.4.1-rc9
v2.4.2
v2.4.2-rc1
v2.4.3
v2.4.3-rc1
v2.4.4
v2.4.4-rc1
v2.4.4-rc2
v2.4.4-rc3
v2.4.5
v2.4.5-rc1
v2.4.5-rc2
v2.4.6
v2.4.6-rc1
v2.4.6-rc2
v2.4.6-rc3
v2.4.6-rc4
v2.4.6-rc5
v2.4.6-rc6
v2.4.6-rc7
v2.4.6-rc8
v2.4.7
v2.4.7-rc1
v2.4.7-rc2
v2.4.7-rc3
v3.*
v3.0.0
v3.0.0-preview
v3.0.0-preview-rc1
v3.0.0-preview-rc2
v3.0.0-preview2
v3.0.0-preview2-rc1
v3.0.0-preview2-rc2
v3.0.0-rc1
v3.0.0-rc2
v3.0.0-rc3
v3.0.1
v3.0.1-rc1
v3.0.1-rc2
v3.0.1-rc3
v3.0.2
v3.0.2-rc1
v3.0.3
v3.0.3-rc1
v3.1.0-rc1
v3.1.1
v3.1.1-rc1
v3.1.1-rc2
v3.1.1-rc3
v3.1.2
v3.1.2-rc1
v3.1.3
v3.1.3-rc1
v3.1.3-rc2
v3.1.3-rc3
v3.1.3-rc4
v3.2.0
v3.2.0-rc1
v3.2.0-rc2
v3.2.0-rc3
v3.2.0-rc4
v3.2.0-rc5
v3.2.0-rc6
v3.2.0-rc7
v3.2.1
v3.2.1-rc1
v3.2.1-rc2
v3.2.2
v3.2.2-rc1
v3.2.3
v3.2.3-rc1
v3.2.4
v3.2.4-rc1
v3.3.0
v3.3.0-rc1
v3.3.0-rc2
v3.3.0-rc3
v3.3.0-rc4
v3.3.0-rc5
v3.3.0-rc6
v3.3.1
v3.3.1-rc1
v3.3.1-rc2
v3.3.1-rc3
v3.3.1-rc4
v3.3.2
v3.3.2-rc1
v3.3.3
v3.3.3-rc1
v3.3.4
v3.3.4-rc1
v3.4.0
v3.4.0-rc1
v3.4.0-rc2
v3.4.0-rc3
v3.4.0-rc4
v3.4.0-rc5
v3.4.0-rc6
v3.4.0-rc7
v3.4.1
v3.4.1-rc1
v3.4.2
v3.4.2-rc1
v3.4.3
v3.4.3-rc1
v3.4.3-rc2
v3.4.4
v3.4.4-rc1
v3.5.0
v3.5.0-rc1
v3.5.0-rc2
v3.5.0-rc3
v3.5.0-rc4
v3.5.0-rc5
v3.5.1
v3.5.1-rc1
v3.5.1-rc2
v3.5.2
v3.5.2-rc1
v3.5.2-rc2
v3.5.2-rc3
v3.5.2-rc4
v3.5.2-rc5
v3.5.3
v3.5.3-rc1
v3.5.3-rc2
v3.5.3-rc3
v3.5.4
v3.5.4-rc1
v3.5.4-rc2
v3.5.4-rc3
v3.5.5
v3.5.5-rc1
v3.5.6
v3.5.7
v3.5.7-rc1
v3.5.8
v3.5.8-rc1
v4.*
v4.0.0
v4.0.0-preview1
v4.0.0-preview1-rc1
v4.0.0-preview1-rc2
v4.0.0-preview1-rc3
v4.0.0-preview2
v4.0.0-preview2-rc1
v4.0.0-rc1
v4.0.0-rc2
v4.0.0-rc3
v4.0.0-rc4
v4.0.0-rc5
v4.0.0-rc6
v4.0.0-rc7
v4.0.1
v4.0.1-rc1
v4.0.2
v4.0.2-rc1
v4.1.0
v4.1.0-preview1
v4.1.0-preview1-rc1
v4.1.0-preview2
v4.1.0-preview2-rc1
v4.1.0-preview3
v4.1.0-preview3-rc1
v4.1.0-preview4
v4.1.0-preview4-rc1
v4.1.0-rc1
v4.1.0-rc2
v4.1.0-rc3
v4.1.1
v4.1.1-rc1
v4.1.1-rc2
v4.2.0-preview1
v4.2.0-preview1-rc1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-20445.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "8.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "9.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "10.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "33"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "18.04"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "2"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "7.2"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "7.3"
            }
        ]
    }
]