CVE-2021-21409
Possible request smuggling in HTTP/2 due missing validation of content-length
描述
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.61.Final there is a vulnerability that enables request smuggling. The content-length header is not correctly validated if the request only uses a single Http2HeaderFrame with the endStream set to to true. This could lead to request smuggling if the request is proxied to a remote peer and translated to HTTP/1.1. This is a followup of GHSA-wm47-8v5p-wjpj/CVE-2021-21295 which did miss to fix this one case. This was fixed as part of 4.1.61.Final.
如何修補 CVE-2021-21409
要修補 CVE-2021-21409,請將受影響套件升級到下列已修補版本。
- —升級至 1:4.1.48-4 或更新版本
- —未列出修補版本
- —升級至 4.1.61.Final 或更新版本
- —未列出修補版本
CVE-2021-21409 正在被利用嗎?
低 — EPSS 為 4.9%,目前沒有觀察到大規模利用活動。
受影響套件(4)
- from 0, < 1:4.1.48-4
- from 0
- >= 4.0.0, < 4.1.61.Final
- from 0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.9 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |