Description
HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header.
Remediation
References
Related Vulnerabilities
Liferay Portal Inefficient Regular Expression Complexity Vulnerability (CVE-2023-33950)
WordPress 3.9.x Multiple Vulnerabilities (3.9 - 3.9.10)
WordPress Plugin Daily Inspiration Generator Cross-Site Scripting (2.0)
WordPress Plugin Cooked Pro Cross-Site Scripting (1.7.5.5)
Plone CMS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-5497)