Inconsistent interpretation of HTTP requests in Netty - CVE-2021-21409

 

Inconsistent interpretation of HTTP requests in Netty - CVE-2021-21409

Published: April 1, 2021 / Updated: February 11, 2025


Vulnerability identifier: #VU51837
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-21409
CWE-ID: CWE-444
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to preform HTTP request smuggling attacks.

The vulnerability exists due to improper validation of HTTP requests in io.netty:netty-codec-http2 in Netty, if the request only uses a single Http2HeaderFrame with the endStream set to to true. A remote attacker can send a specially crafted HTTP request to the server and smuggle arbitrary HTTP headers.

Successful exploitation of vulnerability may allow an attacker to poison HTTP cache and perform phishing attacks.


Affected software

Netty
IBM Observability with Instana
Log Analysis
IBM Operations Analytics Predictive Insights
IBM Cloud Transformation Advisor
AMQ Clients
IBM Watson Knowledge Catalog in Cloud Pak for Data
OpenShift Logging
Oracle Communications Design Studio
Netcool Operations Insight
Dell Secure Connect Gateway
IBM Sterling B2B Integrator
qpid-proton (Red Hat package)
netty (Debian package)
libnetty-java (Ubuntu package)
netty-help
netty
netty-poms
netty-javadoc
AMQ Streams
JBoss Enterprise Application Platform
AMQ Broker
Primavera Gateway
Fuse
Oracle Communications Cloud Native Core Console
Oracle Communications Cloud Native Core Policy
Planning Analytics Local
Apache Pulsar
Oracle Communications Instant Messaging Server
Security QRadar EDR
DataStage on Cloud Pak for Data
Dell EMC OpenManage Enterprise Services
IBM Sterling Order Management
Oracle Communications BRM - Elastic Charging Engine
Oracle NoSQL Database
openSUSE Leap
Ubuntu
openEuler
Cloud Pak for Security (CP4S)
IBM Qradar SIEM
IBM Security Guardium

How to mitigate CVE-2021-21409

Install updates from vendor's website.

Netty - update to 4.1.61
qpid-proton (Red Hat package) - addressed in versions 0.33.0-6.el7_9, 0.33.0-8.el8
Log Analysis - update to 1.3.8
IBM Operations Analytics Predictive Insights - update to 1.3.6.8
AMQ Streams - update to 1.8.0
Planning Analytics Local - update to 2.0.1
Apache Pulsar - update to 2.8.0
IBM Cloud Transformation Advisor - update to 3.2.1
Security QRadar EDR - update to 3.12.15
netty (Debian package) - update to 1:4.1.33-1+deb10u2
DataStage on Cloud Pak for Data - update to 4.8.5
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.8, 4.8.9, 5.1.1, 5.1.2, 5.1.3
OpenShift Logging - addressed in versions 5.1.9, 5.2.8
JBoss Enterprise Application Platform - update to 7.3.8
AMQ Broker - addressed in versions 7.8.2, 7.9.0
libnetty-java (Ubuntu package) - addressed in versions Ubuntu Pro, 1:4.1.48-4+deb11u1build0.22.04.1, 1:4.1.48-5ubuntu0.1
Dell EMC OpenManage Enterprise Services - update to 1.2
Netcool Operations Insight - update to 1.6.6
Cloud Pak for Security (CP4S) - update to 1.10.12.0
netty-help - update to 4.1.13-11
netty - update to 4.1.13-11
netty-poms - update to 4.1.75-150200.4.9.1
netty - update to 4.1.75-150200.4.9.1
netty-javadoc - update to 4.1.75-150200.4.9.1
Dell Secure Connect Gateway - update to 5.0
IBM Sterling B2B Integrator - addressed in versions 6.0.3.7, 6.1.0.5, 6.1.1.1, 6.1.2.0
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 9, 7.5.0 Update Pack 5
Fuse - update to 7.10.0
IBM Sterling Order Management - update to 10.0.0.29
IBM Security Guardium - addressed in versions 11.0p360, 11.0p430
Oracle NoSQL Database - update to 21.1.12

External References

Related Security Bulletins