Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-21409


Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.61.Final there is a vulnerability that enables request smuggling. The content-length header is not correctly validated if the request only uses a single Http2HeaderFrame with the endStream set to to true. This could lead to request smuggling if the request is proxied to a remote peer and translated to HTTP/1.1. This is a followup of GHSA-wm47-8v5p-wjpj/CVE-2021-21295 which did miss to fix this one case. This was fixed as part of 4.1.61.Final.


Published

2021-03-30T15:15:14.573

Last Modified

2024-11-21T05:48:17.963

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.9 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-444
  • Type: Primary
    CWE-444

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application netty netty < 4.1.61 Yes
Operating System debian debian_linux 10.0 Yes
Application netapp oncommand_api_services - Yes
Application netapp oncommand_workflow_automation - Yes
Application oracle banking_corporate_lending_process_management 14.2.0 Yes
Application oracle banking_corporate_lending_process_management 14.3.0 Yes
Application oracle banking_corporate_lending_process_management 14.5.0 Yes
Application oracle banking_credit_facilities_process_management 14.2.0 Yes
Application oracle banking_credit_facilities_process_management 14.3.0 Yes
Application oracle banking_credit_facilities_process_management 14.5.0 Yes
Application oracle banking_trade_finance_process_management 14.2.0 Yes
Application oracle banking_trade_finance_process_management 14.3.0 Yes
Application oracle banking_trade_finance_process_management 14.5.0 Yes
Application oracle coherence 12.2.1.4.0 Yes
Application oracle coherence 14.1.1.0.0 Yes
Application oracle communications_brm_-_elastic_charging_engine 12.0.0.3 Yes
Application oracle communications_cloud_native_core_console 1.7.0 Yes
Application oracle communications_cloud_native_core_policy 1.14.0 Yes
Application oracle communications_design_studio 7.4.2.0.0 Yes
Application oracle communications_messaging_server 8.1 Yes
Application oracle helidon 1.4.10 Yes
Application oracle helidon 2.4.0 Yes
Application oracle jd_edwards_enterpriseone_tools < 9.2.6.3 Yes
Application oracle nosql_database < 21.1.12 Yes
Application oracle primavera_gateway ≤ 17.12.11 Yes
Application oracle primavera_gateway ≤ 18.8.11 Yes
Application oracle primavera_gateway ≤ 19.12.10 Yes
Application quarkus quarkus ≤ 1.13.7 Yes

References