A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling.
CVE: (none) => CVE-2020-10719
Dropped in Cauldron. As there is no maintainer for this package I added the committers in CC. (Please set the status to 'assigned' if you are working on it)
CC: (none) => mageia, ouaurelien
Assignee: bugsquad => pkg-bugs
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10719 https://security-tracker.debian.org/tracker/CVE-2020-10719
Summary: undertow security issue CVE-2020-10719 => undertow new security issue CVE-2020-10719Severity: normal => majorAssignee: pkg-bugs => javaStatus comment: (none) => Fixed upstream in 2.1.1
Done for mga7!
CC: (none) => geiger.david68210
Advisory: ======================== Updated undertow packages fix security vulnerability: A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling (CVE-2020-10719). References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10719 ======================== Updated packages in core/updates_testing: ======================== undertow-1.4.0-2.1.mga7 undertow-javadoc-1.4.0-2.1.mga7 from undertow-1.4.0-2.1.mga7.src.rpm
Assignee: java => qa-bugsStatus comment: Fixed upstream in 2.1.1 => (none)
Installed both packages, and updated. No installation issues. Looked back for another bug for this package, and only found an obscure reference in a bug concerning a differnt package, which is also been dropped for Mageia 8. OKing this on a clean install. Validatingt. Advisory in Comment 4.
Whiteboard: (none) => MGA7-64-OKKeywords: (none) => validated_updateCC: (none) => andrewsfarm, sysadmin-bugs
Advisory pushed to SVN.
Keywords: (none) => advisory
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2021-0052.html
Status: NEW => RESOLVEDResolution: (none) => FIXED