Inconsistent interpretation of HTTP requests in Netty - CVE-2020-7238
Published: February 14, 2020 / Updated: February 26, 2020
Vulnerability identifier: #VU25353
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-7238
CWE-ID: CWE-444
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform HTTP request smuggling attack.
The vulnerability exists due to improper input validation when processing a whitespace before the colon in HTTP headers (e.g. "Transfer-Encoding : chunked") and a later Content-Length header. A remote attacker can send a specially crafted HTTP request and perform HTTP request smuggling attack.
This issue exists because of an incomplete fix for CVE-2019-16869 (SB2019092616).
Affected software
Netty
IBM Observability with Instana
Log Analysis
AMQ Clients
Autodesk Infraworks
IBM Spectrum Protect Plus
AMQ Streams
AMQ Broker
JBoss Enterprise Application Platform
netty (Debian package)
eap7-h2database (Red Hat package)
eap7-avro (Red Hat package)
eap7-bouncycastle (Red Hat package)
eap7-jboss-marshalling (Red Hat package)
eap7-xalan-j2 (Red Hat package)
eap7-jackson-databind (Red Hat package)
jctools
eap7-apache-cxf (Red Hat package)
eap7-jboss-xnio-base (Red Hat package)
libnetty-3.9-java (Ubuntu package)
libnetty-java (Ubuntu package)
netty
eap7-wildfly (Red Hat package)
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Ubuntu
Fedora
Red Hat Single Sign-On
IBM Sterling Order Management
IBM Observability with Instana
Log Analysis
AMQ Clients
Autodesk Infraworks
IBM Spectrum Protect Plus
AMQ Streams
AMQ Broker
JBoss Enterprise Application Platform
netty (Debian package)
eap7-h2database (Red Hat package)
eap7-avro (Red Hat package)
eap7-bouncycastle (Red Hat package)
eap7-jboss-marshalling (Red Hat package)
eap7-xalan-j2 (Red Hat package)
eap7-jackson-databind (Red Hat package)
jctools
eap7-apache-cxf (Red Hat package)
eap7-jboss-xnio-base (Red Hat package)
libnetty-3.9-java (Ubuntu package)
libnetty-java (Ubuntu package)
netty
eap7-wildfly (Red Hat package)
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Ubuntu
Fedora
Red Hat Single Sign-On
IBM Sterling Order Management
How to mitigate CVE-2020-7238
Install updates from vendor's website.
Netty - update to 4.1.45
AMQ Streams - update to 1.4.0
Log Analysis - update to 1.3.8
AMQ Clients - update to 2.6.0
netty (Debian package) - update to 1:4.1.33-1+deb10u2
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.8.0
AMQ Broker - addressed in versions 7.4.3, 7.6
JBoss Enterprise Application Platform - addressed in versions 7.1.8, 7.2.7
Autodesk Infraworks - addressed in versions 2021.2 Hotfix 9, 2023.1 Hotfix 1
eap7-h2database (Red Hat package) - update to 1.4.197-2.redhat_00005.1.ep7.el7
eap7-avro (Red Hat package) - update to 1.7.6-2.redhat_00003.1.ep7.el7
eap7-bouncycastle (Red Hat package) - update to 1.68.0-1.redhat_00005.1.ep7.el7
eap7-jboss-marshalling (Red Hat package) - update to 2.0.15-1.Final_redhat_00001.1.ep7.el7
eap7-xalan-j2 (Red Hat package) - update to 2.7.1-26.redhat_00015.1.ep7.el7
eap7-jackson-databind (Red Hat package) - update to 2.8.11.6-1.SP1_redhat_00001.1.ep7.el7
jctools - update to 3.1.0-1.fc33
eap7-apache-cxf (Red Hat package) - update to 3.1.16-3.SP1_redhat_00001.1.ep7.el7
eap7-jboss-xnio-base (Red Hat package) - update to 3.5.10-1.Final_redhat_00001.1.ep7.el7
libnetty-3.9-java (Ubuntu package) - update to 3.9.0.Final-1ubuntu0.1
libnetty-java (Ubuntu package) - update to 1:4.1.7-4ubuntu0.1
netty - update to 4.1.51-1.fc33
eap7-wildfly (Red Hat package) - update to 7.1.8-2.GA_redhat_00002.1.ep7.el7
Red Hat Single Sign-On - update to 7.3.7
IBM Sterling Order Management - update to 10.0.2206.2
IBM Spectrum Protect Plus - update to 10.1.6.4
AMQ Streams - update to 1.4.0
Log Analysis - update to 1.3.8
AMQ Clients - update to 2.6.0
netty (Debian package) - update to 1:4.1.33-1+deb10u2
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.8.0
AMQ Broker - addressed in versions 7.4.3, 7.6
JBoss Enterprise Application Platform - addressed in versions 7.1.8, 7.2.7
Autodesk Infraworks - addressed in versions 2021.2 Hotfix 9, 2023.1 Hotfix 1
eap7-h2database (Red Hat package) - update to 1.4.197-2.redhat_00005.1.ep7.el7
eap7-avro (Red Hat package) - update to 1.7.6-2.redhat_00003.1.ep7.el7
eap7-bouncycastle (Red Hat package) - update to 1.68.0-1.redhat_00005.1.ep7.el7
eap7-jboss-marshalling (Red Hat package) - update to 2.0.15-1.Final_redhat_00001.1.ep7.el7
eap7-xalan-j2 (Red Hat package) - update to 2.7.1-26.redhat_00015.1.ep7.el7
eap7-jackson-databind (Red Hat package) - update to 2.8.11.6-1.SP1_redhat_00001.1.ep7.el7
jctools - update to 3.1.0-1.fc33
eap7-apache-cxf (Red Hat package) - update to 3.1.16-3.SP1_redhat_00001.1.ep7.el7
eap7-jboss-xnio-base (Red Hat package) - update to 3.5.10-1.Final_redhat_00001.1.ep7.el7
libnetty-3.9-java (Ubuntu package) - update to 3.9.0.Final-1ubuntu0.1
libnetty-java (Ubuntu package) - update to 1:4.1.7-4ubuntu0.1
netty - update to 4.1.51-1.fc33
eap7-wildfly (Red Hat package) - update to 7.1.8-2.GA_redhat_00002.1.ep7.el7
Red Hat Single Sign-On - update to 7.3.7
IBM Sterling Order Management - update to 10.0.2206.2
IBM Spectrum Protect Plus - update to 10.1.6.4
External References
Related Security Bulletins
- HTTP request smuggling in Netty
- Red Hat JBoss Enterprise Application Platform update for netty
- Red Hat AMQ Clients update for Netty
- Multiple vulnerabilities in JBoss Enterprise Application Platform
- Multiple vulnerabilities in Red Hat AMQ Streams
- Multiple vulnerabilities in Red Hat AMQ Broker
- Multiple vulnerabilities in Red Hat Process Automation Manager
- Debian update for netty
- Multiple vulnerabilities in Autodesk InfraWorks
- Multiple vulnerabilities in IBM Observability with Instana (OnPrem)
- Multiple vulnerabilities in IBM Sterling Order Management
- Multiple vulnerabilities in IBM Operations Analytics - Log Analysis
- Multiple vulnerabilities in Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
- Multiple vulnerabilities in IBM Spectrum Protect Plus
- Ubuntu update for netty-3.9
- Ubuntu update for netty
- Multiple vulnerabilities in Red Hat Single Sign-On 7.3
- Multiple vulnerabilities in AMQ Broker 7.4
- Fedora 33 update for jctools, netty