Back

CRITICAL

netty: HttpObjectDecoder.java allows Content-Length header to accompanied by second Content-Length header

Published Jan 29, 2020

Description

HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header.

Affected products

Remediation

Red Hat statement

OpenShift Container Platform ships a vulnerable netty library as part of the logging-elasticsearch5 container. ElasticSearch's security team has stated that the previous vulnerability, CVE-2019-16869, does not poses a substantial practical threat to ElasticSearch 6 [1]. We agree that this issue would be difficult to exploit both these vulnerabilities on OpenShift Container Platform, so we're reducing the impact of this issue to moderate and may fix it in the future release. Red Hat Satellite ships a vulnerable version of netty embedded in Candlepin. However, the flaw can not be triggered in that context, because HTTP requests are handled by Tomcat, not by netty. A future release may fix this. [1] https://github.com/elastic/elasticsearch/issues/49396

Red Hat mitigation

* Use HTTP/2 instead (clear boundaries between requests) * Disable reuse of backend connections eg. ```http-reuse never``` in HAProxy or whatever equivalent LB settings

Weaknesses (1)

References (97)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 29, 2020
Updated Aug 5, 2024
Reserved Jan 29, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jan 29, 2020
GHSA-P2V9-G2QV-P635