First published: Tue Mar 03 2020(Updated: )
This release of Red Hat build of Eclipse Vert.x 3.8.5 includes security updates, bug fixes, and enhancements. For more information, see the release notes page listed in the References section.<br>Security Fix(es):<br><li> netty: HTTP request smuggling (CVE-2019-20444)</li> <li> netty: HttpObjectDecoder.java allows Content-Length header to accompanied by second Content-Length header (CVE-2019-20445)</li> <li> netty: HTTP Request Smuggling due to Transfer-Encoding whitespace mishandling (CVE-2020-7238)</li> For more details about the security issues and their impact, the CVSS score, acknowledgements, and other related information, see the CVE pages listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2020:0567 is classified as important.
To fix RHSA-2020:0567, update to the latest Red Hat build of Eclipse Vert.x that includes the security patches.
RHSA-2020:0567 addresses a security vulnerability related to HTTP request smuggling (CVE-2019-20444).
RHSA-2020:0567 affects Red Hat Eclipse Vert.x version 3.8.5 and earlier.
Yes, it is recommended to apply RHSA-2020:0567 immediately to mitigate potential security risks.