CVE-2021-21409Medium· 5.9▾ SunlitNetty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.61.Final there i…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
4.9%
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.61.Final there is a vulnerability that enables request smuggling. The content-length header is not correctly validated if the request only uses a single Http2HeaderFrame with the endStream set to to true. This could lead to request smuggling if the request is proxied to a remote peer and translated to HTTP/1.1. This is a followup of GHSA-wm47-8v5p-wjpj/CVE-2021-21295 which did miss to fix this one case. This was fixed as part of 4.1.61.Final.
netty < 4.1.61debian_linux = 10.0oncommand_api_servicesoncommand_workflow_automationbanking_corporate_lending_process_management = 14.2.0banking_corporate_lending_process_management = 14.3.0banking_corporate_lending_process_management = 14.5.0banking_credit_facilities_process_management = 14.2.0banking_credit_facilities_process_management = 14.3.0banking_credit_facilities_process_management = 14.5.0banking_trade_finance_process_management = 14.2.0banking_trade_finance_process_management = 14.3.0banking_trade_finance_process_management = 14.5.0coherence = 12.2.1.4.0coherence = 14.1.1.0.0communications_brm_-_elastic_charging_engine = 12.0.0.3communications_cloud_native_core_console = 1.7.0communications_cloud_native_core_policy = 1.14.0communications_design_studio = 7.4.2.0.0communications_messaging_server = 8.1helidon = 1.4.10helidon = 2.4.0jd_edwards_enterpriseone_tools < 9.2.6.3nosql_database < 21.1.12primavera_gateway >= 17.12.0, <= 17.12.11primavera_gateway >= 18.8.0, <= 18.8.11primavera_gateway >= 19.12.0, <= 19.12.10quarkus <= 1.13.7Upgrade past the affected range:
netty 4.1.61jd_edwards_enterpriseone_tools 9.2.6.3nosql_database 21.1.12Connected by shared product, vendor, weakness, or advisory.
CVE-2021-21295Medium· 5.9Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients
CVE-2021-43797Medium· 6.5Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients
CVE-2019-20444Critical· 9.1HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an "invalid fold."
CVE-2019-20445Critical· 9.1HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header.
CVE-2021-37136High· 7.5The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression)
CVE-2021-37137High· 7.5The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage