MEDIUM · 5.9

CVE-2021-21409

Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2...

Vulnerability Description

Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.61.Final there is a vulnerability that enables request smuggling. The content-length header is not correctly validated if the request only uses a single Http2HeaderFrame with the endStream set to to true. This could lead to request smuggling if the request is proxied to a remote peer and translated to HTTP/1.1. This is a followup of GHSA-wm47-8v5p-wjpj/CVE-2021-21295 which did miss to fix this one case. This was fixed as part of 4.1.61.Final.

CVSS Score

5.9

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
NettyNetty< 4.1.61
DebianDebian Linux10.0
NetappOncommand Api Services-
NetappOncommand Workflow Automation-
OracleBanking Corporate Lending Process Management14.2.0
OracleBanking Credit Facilities Process Management14.2.0
OracleBanking Trade Finance Process Management14.2.0
OracleCoherence12.2.1.4.0
OracleCommunications Brm - Elastic Charging Engine12.0.0.3
OracleCommunications Cloud Native Core Console1.7.0
OracleCommunications Cloud Native Core Policy1.14.0
OracleCommunications Design Studio7.4.2.0.0
OracleCommunications Messaging Server8.1
OracleHelidon1.4.10
OracleJd Edwards Enterpriseone Tools< 9.2.6.3
OracleNosql Database< 21.1.12
OraclePrimavera Gateway>= 17.12.0, <= 17.12.11
QuarkusQuarkus<= 1.13.7

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-21409?

CVE-2021-21409 is a vulnerability with a CVSS score of 5.9 (MEDIUM). Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2...

How severe is CVE-2021-21409?

CVE-2021-21409 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-21409?

Check the references section above for vendor advisories and patch information. Affected products include: Netty Netty, Debian Debian Linux, Netapp Oncommand Api Services, Netapp Oncommand Workflow Automation, Oracle Banking Corporate Lending Process Management.