Inconsistent interpretation of HTTP requests in Netty - CVE-2020-7238

 

Inconsistent interpretation of HTTP requests in Netty - CVE-2020-7238

Published: February 14, 2020 / Updated: February 26, 2020


Vulnerability identifier: #VU25353
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-7238
CWE-ID: CWE-444
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform HTTP request smuggling attack.

The vulnerability exists due to improper input validation when processing a whitespace before the colon in HTTP headers (e.g. "Transfer-Encoding : chunked") and a later Content-Length header. A remote attacker can send a specially crafted HTTP request and perform HTTP request smuggling attack.

This issue exists because of an incomplete fix for CVE-2019-16869 (SB2019092616).


Affected software

Netty
IBM Observability with Instana
Log Analysis
AMQ Clients
Autodesk Infraworks
IBM Spectrum Protect Plus
AMQ Streams
AMQ Broker
JBoss Enterprise Application Platform
netty (Debian package)
eap7-h2database (Red Hat package)
eap7-avro (Red Hat package)
eap7-bouncycastle (Red Hat package)
eap7-jboss-marshalling (Red Hat package)
eap7-xalan-j2 (Red Hat package)
eap7-jackson-databind (Red Hat package)
jctools
eap7-apache-cxf (Red Hat package)
eap7-jboss-xnio-base (Red Hat package)
libnetty-3.9-java (Ubuntu package)
libnetty-java (Ubuntu package)
netty
eap7-wildfly (Red Hat package)
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Ubuntu
Fedora
Red Hat Single Sign-On
IBM Sterling Order Management

How to mitigate CVE-2020-7238

Install updates from vendor's website.

Netty - update to 4.1.45
AMQ Streams - update to 1.4.0
Log Analysis - update to 1.3.8
AMQ Clients - update to 2.6.0
netty (Debian package) - update to 1:4.1.33-1+deb10u2
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.8.0
AMQ Broker - addressed in versions 7.4.3, 7.6
JBoss Enterprise Application Platform - addressed in versions 7.1.8, 7.2.7
Autodesk Infraworks - addressed in versions 2021.2 Hotfix 9, 2023.1 Hotfix 1
eap7-h2database (Red Hat package) - update to 1.4.197-2.redhat_00005.1.ep7.el7
eap7-avro (Red Hat package) - update to 1.7.6-2.redhat_00003.1.ep7.el7
eap7-bouncycastle (Red Hat package) - update to 1.68.0-1.redhat_00005.1.ep7.el7
eap7-jboss-marshalling (Red Hat package) - update to 2.0.15-1.Final_redhat_00001.1.ep7.el7
eap7-xalan-j2 (Red Hat package) - update to 2.7.1-26.redhat_00015.1.ep7.el7
eap7-jackson-databind (Red Hat package) - update to 2.8.11.6-1.SP1_redhat_00001.1.ep7.el7
jctools - update to 3.1.0-1.fc33
eap7-apache-cxf (Red Hat package) - update to 3.1.16-3.SP1_redhat_00001.1.ep7.el7
eap7-jboss-xnio-base (Red Hat package) - update to 3.5.10-1.Final_redhat_00001.1.ep7.el7
libnetty-3.9-java (Ubuntu package) - update to 3.9.0.Final-1ubuntu0.1
libnetty-java (Ubuntu package) - update to 1:4.1.7-4ubuntu0.1
netty - update to 4.1.51-1.fc33
eap7-wildfly (Red Hat package) - update to 7.1.8-2.GA_redhat_00002.1.ep7.el7
Red Hat Single Sign-On - update to 7.3.7
IBM Sterling Order Management - update to 10.0.2206.2
IBM Spectrum Protect Plus - update to 10.1.6.4

External References

Related Security Bulletins