Description
HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header.
Remediation
References
Related Vulnerabilities
MediaWiki CVE-2023-29140 Vulnerability (CVE-2023-29140)
WebLogic Improper Input Validation Vulnerability (CVE-2021-45105)
OpenSSL Out-of-bounds Write Vulnerability (CVE-2016-6303)
Liferay Portal URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2021-33331)
Ruby on Rails Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-0449)