CVE-2021-21290
Last modified
CVE-2021-21290 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty before version 4.1.59.Final there is a vulnerability on Unix-like systems involving an insecure temp file. EPSS estimates a 1.78% chance of exploitation in the next 30 days.
Description
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty before version 4.1.59.Final there is a vulnerability on Unix-like systems involving an insecure temp file. When netty's multipart decoders are used local information disclosure can occur via the local system temporary directory if temporary storing uploads on the disk is enabled. On unix-like systems, the temporary directory is shared between all user. As such, writing to this directory using APIs that do not explicitly set the file/directory permissions can lead to information disclosure. Of note, this does not impact modern MacOS Operating Systems. The method "File.createTempFile" on unix-like systems creates a random file, but, by default will create this file with the permissions "-rw-r--r--". Thus, if sensitive information is written to this file, other local users can read this information. This is the case in netty's "AbstractDiskHttpData" is vulnerable. This has been fixed in version 4.1.59.Final. As a workaround, one may specify your own "java.io.tmpdir" when you start the JVM or use "DefaultHttpDataFactory.setBaseDir(...)" to set the directory to something that is only readable by the current user.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Netty | Netty | < 4.1.59 |
| Debian | Debian Linux | 9.0 |
| Debian | Debian Linux | 10.0 |
| Quarkus | Quarkus | <= 1.13.7 |
| Oracle | Banking Corporate Lending Process Management | 14.2.0 |
| Oracle | Banking Corporate Lending Process Management | 14.3.0 |
| Oracle | Banking Corporate Lending Process Management | 14.5.0 |
| Oracle | Banking Credit Facilities Process Management | 14.2.0 |
| Oracle | Banking Credit Facilities Process Management | 14.3.0 |
| Oracle | Banking Credit Facilities Process Management | 14.5.0 |
| Oracle | Banking Trade Finance Process Management | 14.2.0 |
| Oracle | Banking Trade Finance Process Management | 14.3.0 |
| Oracle | Banking Trade Finance Process Management | 14.5.0 |
| Oracle | Communications Brm - Elastic Charging Engine | 12.0.0.3 |
| Oracle | Communications Design Studio | 7.4.2 |
| Oracle | Communications Messaging Server | 8.1 |
| Oracle | Nosql Database | < 20.3 |
| Netapp | Active Iq Unified Manager | All versions |
| Netapp | Cloud Secure Agent | All versions |
| Netapp | Snapcenter | All versions |
References
- https://github.com/netty/netty/commit/c735357bf29d07856ad171c6611a2e1a0e0000ecPatch, Third Party Advisory
- https://github.com/netty/netty/security/advisories/GHSA-5mcr-gq6c-3hq2Exploit, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/02/msg00016.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220210-0011/Third Party Advisory
- https://www.debian.org/security/2021/dsa-4885Third Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatch, Third Party Advisory
- https://github.com/netty/netty/commit/c735357bf29d07856ad171c6611a2e1a0e0000ecPatch, Third Party Advisory
- https://github.com/netty/netty/security/advisories/GHSA-5mcr-gq6c-3hq2Exploit, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/02/msg00016.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220210-0011/Third Party Advisory
- https://www.debian.org/security/2021/dsa-4885Third Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.htmlThird Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-21290?
How severe is CVE-2021-21290?
How do I fix CVE-2021-21290?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-21285In Docker before versions 9.03.15, 20.10.3 there is a vulner…6.5
- CVE-2021-21286AVideo Platform is an open-source Audio and Video platform. …8.8
- CVE-2021-21287MinIO is a High Performance Object Storage released under Ap…7.7
- CVE-2021-21288CarrierWave is an open-source RubyGem which provides a simpl…4.3
- CVE-2021-21289Mechanize is an open-source ruby library that makes automate…8.3
- CVE-2021-2129Vulnerability in the Oracle VM VirtualBox product of Oracle …7.9
- CVE-2021-21291OAuth2 Proxy is an open-source reverse proxy and static file…6.1
- CVE-2021-21292Traccar is an open source GPS tracking system. In Traccar be…6.3
- CVE-2021-21293blaze is a Scala library for building asynchronous pipelines…7.5
- CVE-2021-21294Http4s (http4s-blaze-server) is a minimal, idiomatic Scala i…7.5
- CVE-2021-21295Netty is an open-source, asynchronous event-driven network a…5.9
- CVE-2021-21296Fleet is an open source osquery manager. In Fleet before ver…2.7
Are you affected by CVE-2021-21290?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
