Description
Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling.
Remediation
References
Related Vulnerabilities
Drupal Core 7.x Multiple Security Bypass Vulnerabilities (7.0 - 7.25)
TYPO3 Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-3664)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-2080)
Drupal Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2017-6931)