Description
HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header.
Remediation
References
Related Vulnerabilities
concrete5 Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-8082)
PHP Out-of-bounds Read Vulnerability (CVE-2019-11046)
WordPress Plugin Ad Blocker Notify Lite Cross-Site Scripting (2.4.0)
WordPress Plugin 3dady real-time web stats Cross-Site Request Forgery (1.0)
WordPress Plugin AGP Font Awesome Collection Cross-Site Scripting (2.7.2)