MEDIUM · 6.5

CVE-2021-43797

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. Netty prior to version 4.1.71.Final skips control...

Vulnerability Description

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. Netty prior to version 4.1.71.Final skips control chars when they are present at the beginning / end of the header name. It should instead fail fast as these are not allowed by the spec and could lead to HTTP request smuggling. Failing to do the validation might cause netty to "sanitize" header names before it forward these to another remote system when used as proxy. This remote system can't see the invalid usage anymore, and therefore does not do the validation itself. Users should upgrade to version 4.1.71.Final.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
NettyNetty< 4.1.71
QuarkusQuarkus< 2.5.3
NetappOncommand Workflow Automation-
NetappSnapcenter-
OracleBanking Deposits And Lines Of Credit Servicing2.7
OracleBanking Party Management2.7.0
OracleBanking Platform2.6.2
OracleCoherence12.2.1.4.0
OracleCommunications Cloud Native Core Binding Support Function1.11.0
OracleCommunications Cloud Native Core Network Slice Selection Function1.8.0
OracleCommunications Cloud Native Core Policy1.15.0
OracleCommunications Cloud Native Core Security Edge Protection Proxy1.7.0
OracleCommunications Cloud Native Core Unified Data Repository1.15.0
OracleCommunications Design Studio7.4.2
OracleCommunications Instant Messaging Server8.1
OracleHelidon1.4.10
OraclePeoplesoft Enterprise Peopletools8.58
DebianDebian Linux10.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-43797?

CVE-2021-43797 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. Netty prior to version 4.1.71.Final skips control...

How severe is CVE-2021-43797?

CVE-2021-43797 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-43797?

Check the references section above for vendor advisories and patch information. Affected products include: Netty Netty, Quarkus Quarkus, Netapp Oncommand Workflow Automation, Netapp Snapcenter, Oracle Banking Deposits And Lines Of Credit Servicing.