Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.
1:4.1.48-101:4.1.48-10ubuntu0.25.10.11:4.1.48-10ubuntu0.25.10.21:4.1.48-101:4.1.48-111:4.1.48-121:4.1.48-131:4.1.48-141:4.1.48-161:3.2.6.Final-21:3.2.6.Final-2+deb8u2build0.14.04.1~esm11:3.2.6.Final-21:4.0.32-11:4.0.33-11:4.0.34-11:4.0.34-1ubuntu0.1~esm11:4.0.34-1ubuntu0.1~esm21:4.0.34-1ubuntu0.1~esm31:4.1.7-41:4.1.7-4ubuntu0.11:4.1.7-4ubuntu0.1+esm11:4.1.7-4ubuntu0.1+esm21:4.1.7-4ubuntu0.1+esm31:4.1.7-4ubuntu0.1+esm41:4.1.7-4ubuntu0.1+esm51:4.1.7-4ubuntu0.1~esm11:4.1.33-11:4.1.33-21:4.1.33-31:4.1.45-11:4.1.45-1ubuntu0.1~esm11:4.1.45-1ubuntu0.1~esm21:4.1.45-1ubuntu0.1~esm31:4.1.45-1ubuntu0.1~esm41:4.1.48-41:4.1.48-4+deb11u1build0.22.04.11:4.1.48-4+deb11u2build0.22.04.11:4.1.48-4+deb11u2ubuntu0.11:4.1.48-4+deb11u2ubuntu0.1+esm11:4.1.48-4+deb11u2ubuntu0.1~esm11:4.1.48-4+deb11u2ubuntu0.1~esm21:4.1.48-71:4.1.48-81:4.1.48-91:4.1.48-9ubuntu0.11:4.1.48-9ubuntu0.1+esm11:4.1.48-9ubuntu0.1~esm11:4.1.48-9ubuntu0.1~esm2Exploitability
AV:NAC:LPR:NUI:NScope
S:UImpact
C:NI:HA:NCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N