HomeNettyCVE-2021-21409

CVE-2021-21409

MEDIUM
5.9CVSS
Published: 2021-03-30
Updated: 2024-11-21
AI Analysis

Description

Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.61.Final there is a vulnerability that enables request smuggling. The content-length header is not correctly validated if the request only uses a single Http2HeaderFrame with the endStream set to to true. This could lead to request smuggling if the request is proxied to a remote peer and translated to HTTP/1.1. This is a followup of GHSA-wm47-8v5p-wjpj/CVE-2021-21295 which did miss to fix this one case. This was fixed as part of 4.1.61.Final.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Vector
network
Complexity
high
Privileges
none
User Action
none
Scope
unchanged
Confidentiality
none
Integrity
high
Availability
none
Weaknesses
CWE-444CWE-444

Metadata

Primary Vendor
NETTY
Published
3/30/2021
Last Modified
11/21/2024
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

netty : nettydebian : debian_linuxnetapp : oncommand_api_servicesnetapp : oncommand_workflow_automationoracle : banking_corporate_lending_process_managementoracle : banking_corporate_lending_process_managementoracle : banking_corporate_lending_process_managementoracle : banking_credit_facilities_process_managementoracle : banking_credit_facilities_process_managementoracle : banking_credit_facilities_process_managementoracle : banking_trade_finance_process_managementoracle : banking_trade_finance_process_managementoracle : banking_trade_finance_process_managementoracle : coherenceoracle : coherenceoracle : communications_brm_-_elastic_charging_engineoracle : communications_cloud_native_core_consoleoracle : communications_cloud_native_core_policyoracle : communications_design_studiooracle : communications_messaging_serveroracle : helidonoracle : helidonoracle : jd_edwards_enterpriseone_toolsoracle : nosql_databaseoracle : primavera_gatewayoracle : primavera_gatewayoracle : primavera_gatewayquarkus : quarkus

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2021-21409 | MEDIUM Severity | CVEDatabase.com | CVEDatabase.com