Inconsistent interpretation of HTTP requests in Netty - CVE-2021-21295

 

Inconsistent interpretation of HTTP requests in Netty - CVE-2021-21295

Published: April 1, 2021 / Updated: February 11, 2025


Vulnerability identifier: #VU51836
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-21295
CWE-ID: CWE-444
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to preform HTTP request smuggling attacks.

The vulnerability exists due to improper validation of HTTP requests in io.netty:netty-codec-http2 when converting HTTP/2 to HTTP/1 streams. A remote attacker can send a specially crafted HTTP request to the server and smuggle arbitrary HTTP headers.

Successful exploitation of vulnerability may allow an attacker to poison HTTP cache and perform phishing attacks.


Affected software

Netty
IBM Observability with Instana
Log Analysis
IBM Operations Analytics Predictive Insights
IBM Cloud Transformation Advisor
AMQ Clients
IBM Watson Knowledge Catalog in Cloud Pak for Data
Autodesk Infraworks
Netcool Operations Insight
Dell Secure Connect Gateway
IBM Watson Machine Learning on CP4D
IBM Spectrum Protect Plus
qpid-proton (Red Hat package)
netty (Debian package)
libnetty-java (Ubuntu package)
netty-help
netty
AMQ Streams
AMQ Broker
Fuse
Security QRadar EDR
DataStage on Cloud Pak for Data
Dell EMC OpenManage Enterprise Services
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
IBM Sterling Order Management
BIG-IQ Centralized Management
Oracle Communications Pricing Design Center
Ubuntu
openEuler
Cloud Pak for Security (CP4S)
IBM Qradar SIEM
Red Hat Single Sign-On
IBM Security Guardium

How to mitigate CVE-2021-21295

Install updates from vendor's website.

Netty - update to 4.1.60
qpid-proton (Red Hat package) - addressed in versions 0.33.0-6.el7_9, 0.33.0-8.el8
Log Analysis - update to 1.3.8
IBM Operations Analytics Predictive Insights - update to 1.3.6.8
AMQ Streams - update to 1.8.0
IBM Cloud Transformation Advisor - update to 3.2.1
Security QRadar EDR - update to 3.12.15
netty (Debian package) - update to 1:4.1.33-1+deb10u2
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.8, 4.8.9, 5.1.1, 5.1.2, 5.1.3
DataStage on Cloud Pak for Data - update to 4.8.5
AMQ Broker - addressed in versions 7.8.2, 7.9.0
Oracle Communications Pricing Design Center - update to 12.0.0.7.0
Autodesk Infraworks - addressed in versions 2021.2 Hotfix 9, 2023.1 Hotfix 1
libnetty-java (Ubuntu package) - addressed in versions Ubuntu Pro, 1:4.1.48-4+deb11u1build0.22.04.1, 1:4.1.48-5ubuntu0.1
Dell EMC OpenManage Enterprise Services - update to 1.2
Netcool Operations Insight - update to 1.6.6
Cloud Pak for Security (CP4S) - update to 1.10.12.0
netty-help - update to 4.1.13-11
netty - update to 4.1.13-11
DB2 on Cloud Pak for Data - update to 4.8.5
DB2 Warehouse on Cloud Pak for Data - update to 4.8.5
Dell Secure Connect Gateway - update to 5.0
IBM Watson Machine Learning on CP4D - update to 5.3.0
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 9, 7.5.0 Update Pack 5
Red Hat Single Sign-On - update to 7.4.7
Fuse - update to 7.10.0
IBM Sterling Order Management - update to 10.0.0.29
IBM Spectrum Protect Plus - update to 10.1.6.4
IBM Security Guardium - addressed in versions 11.0p360, 11.0p430

External References

Related Security Bulletins