CVE-2021-21409
Last modified
CVE-2021-21409 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.61.Final there is a vulnerability that enables request smuggling. EPSS estimates a 4.93% chance of exploitation in the next 30 days.
Description
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.61.Final there is a vulnerability that enables request smuggling. The content-length header is not correctly validated if the request only uses a single Http2HeaderFrame with the endStream set to to true. This could lead to request smuggling if the request is proxied to a remote peer and translated to HTTP/1.1. This is a followup of GHSA-wm47-8v5p-wjpj/CVE-2021-21295 which did miss to fix this one case. This was fixed as part of 4.1.61.Final.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Netty | Netty | < 4.1.61 |
| Debian | Debian Linux | 10.0 |
| Netapp | Oncommand Api Services | All versions |
| Netapp | Oncommand Workflow Automation | All versions |
| Oracle | Banking Corporate Lending Process Management | 14.2.0 |
| Oracle | Banking Corporate Lending Process Management | 14.3.0 |
| Oracle | Banking Corporate Lending Process Management | 14.5.0 |
| Oracle | Banking Credit Facilities Process Management | 14.2.0 |
| Oracle | Banking Credit Facilities Process Management | 14.3.0 |
| Oracle | Banking Credit Facilities Process Management | 14.5.0 |
| Oracle | Banking Trade Finance Process Management | 14.2.0 |
| Oracle | Banking Trade Finance Process Management | 14.3.0 |
| Oracle | Banking Trade Finance Process Management | 14.5.0 |
| Oracle | Coherence | 12.2.1.4.0 |
| Oracle | Coherence | 14.1.1.0.0 |
| Oracle | Communications Brm - Elastic Charging Engine | 12.0.0.3 |
| Oracle | Communications Cloud Native Core Console | 1.7.0 |
| Oracle | Communications Cloud Native Core Policy | 1.14.0 |
| Oracle | Communications Design Studio | 7.4.2.0.0 |
| Oracle | Communications Messaging Server | 8.1 |
| Oracle | Helidon | 1.4.10 |
| Oracle | Helidon | 2.4.0 |
| Oracle | Jd Edwards Enterpriseone Tools | < 9.2.6.3 |
| Oracle | Nosql Database | < 21.1.12 |
| Oracle | Primavera Gateway | >= 17.12.0, <= 17.12.11 |
| Oracle | Primavera Gateway | >= 18.8.0, <= 18.8.11 |
| Oracle | Primavera Gateway | >= 19.12.0, <= 19.12.10 |
| Quarkus | Quarkus | <= 1.13.7 |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21295Third Party Advisory
- https://github.com/netty/netty/commit/b0fa4d5aab4215f3c22ce6123dd8dd5f38dc0432Patch, Third Party Advisory
- https://github.com/netty/netty/security/advisories/GHSA-f256-j965-7f32Third Party Advisory
- https://github.com/netty/netty/security/advisories/GHSA-wm47-8v5p-wjpjThird Party Advisory
- https://security.netapp.com/advisory/ntap-20210604-0003/Third Party Advisory
- https://www.debian.org/security/2021/dsa-4885Third Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatch, Third Party Advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21295Third Party Advisory
- https://github.com/netty/netty/commit/b0fa4d5aab4215f3c22ce6123dd8dd5f38dc0432Patch, Third Party Advisory
- https://github.com/netty/netty/security/advisories/GHSA-f256-j965-7f32Third Party Advisory
- https://github.com/netty/netty/security/advisories/GHSA-wm47-8v5p-wjpjThird Party Advisory
- https://security.netapp.com/advisory/ntap-20210604-0003/Third Party Advisory
- https://www.debian.org/security/2021/dsa-4885Third Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-21409?
How severe is CVE-2021-21409?
How do I fix CVE-2021-21409?
Are you affected by CVE-2021-21409?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
