CVE-2021-21409

Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.61.Final there is a vulnerability that enables request smuggling. The content-length header is not correctly validated if the request only uses a single Http2HeaderFrame with the endStream set to to true. This could lead to request smuggling if the request is proxied to a remote peer and translated to HTTP/1.1. This is a followup of GHSA-wm47-8v5p-wjpj/CVE-2021-21295 which did miss to fix this one case. This was fixed as part of 4.1.61.Final.
HTTP Request/Response Smuggling
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
GitHub_MCNA
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 89%
VendorProductVersion
nettynetty
𝑥
< 4.1.61
debiandebian_linux
10.0
netapponcommand_api_services
-
netapponcommand_workflow_automation
-
oraclebanking_corporate_lending_process_management
14.2.0
oraclebanking_corporate_lending_process_management
14.3.0
oraclebanking_corporate_lending_process_management
14.5.0
oraclebanking_credit_facilities_process_management
14.2.0
oraclebanking_credit_facilities_process_management
14.3.0
oraclebanking_credit_facilities_process_management
14.5.0
oraclebanking_trade_finance_process_management
14.2.0
oraclebanking_trade_finance_process_management
14.3.0
oraclebanking_trade_finance_process_management
14.5.0
oraclecoherence
12.2.1.4.0
oraclecoherence
14.1.1.0.0
oraclecommunications_brm_-_elastic_charging_engine
12.0.0.3
oraclecommunications_cloud_native_core_console
1.7.0
oraclecommunications_cloud_native_core_policy
1.14.0
oraclecommunications_design_studio
7.4.2.0.0
oraclecommunications_messaging_server
8.1
oraclehelidon
1.4.10
oraclehelidon
2.4.0
oraclejd_edwards_enterpriseone_tools
𝑥
< 9.2.6.3
oraclenosql_database
𝑥
< 21.1.12
oracleprimavera_gateway
17.12.0 ≤
𝑥
≤ 17.12.11
oracleprimavera_gateway
18.8.0 ≤
𝑥
≤ 18.8.11
oracleprimavera_gateway
19.12.0 ≤
𝑥
≤ 19.12.10
quarkusquarkus
𝑥
≤ 1.13.7
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
netty
bullseye (security)
1:4.1.48-4+deb11u2
fixed
bullseye
1:4.1.48-4+deb11u2
fixed
stretch
ignored
bookworm
1:4.1.48-7+deb12u1
fixed
bookworm (security)
1:4.1.48-7+deb12u1
fixed
sid
1:4.1.48-10
fixed
trixie
1:4.1.48-10
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
netty
noble
needs-triage
mantic
ignored
lunar
ignored
kinetic
Fixed 1:4.1.48-5ubuntu0.1
released
jammy
Fixed 1:4.1.48-4+deb11u1build0.22.04.1
released
impish
ignored
hirsute
ignored
groovy
ignored
focal
Fixed 1:4.1.45-1ubuntu0.1~esm1
released
bionic
Fixed 1:4.1.7-4ubuntu0.1+esm2
released
xenial
Fixed 1:4.0.34-1ubuntu0.1~esm1
released
trusty
needs-triage
References