Cleartext storage of sensitive information in Netty - CVE-2021-21290

 

Cleartext storage of sensitive information in Netty - CVE-2021-21290

Published: April 1, 2021 / Updated: February 11, 2025


Vulnerability identifier: #VU51835
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-21290
CWE-ID: CWE-312
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to insecure usage of temporary files in AbstractDiskHttpData method in Netty. The application stores sensitive information in temporary file that has insecure permissions. A local user can view application's temporary file and gain access to potentially sensitive data.

Affected software

Netty
IBM Observability with Instana
Log Analysis
IBM Operations Analytics Predictive Insights
AMQ Clients
IBM Watson Knowledge Catalog in Cloud Pak for Data
Oracle Communications Design Studio
Red Hat Decision Manager
Autodesk Infraworks
Netcool Operations Insight
IBM Cloud Transformation Advisor
IBM Watson Assistant for IBM Cloud Pak for Data
Dell Secure Connect Gateway
Red Hat Satellite
IBM Spectrum Protect Plus
qpid-proton (Red Hat package)
pulpcore-selinux (Red Hat package)
tfm-rubygem-katello (Red Hat package)
netty (Debian package)
satellite (Red Hat package)
libnetty-java (Ubuntu package)
netty-help
netty
AMQ Streams
AMQ Broker
Fuse
Planning Analytics Local
PeopleSoft Enterprise PeopleTools
IBM Cloud Private
Security QRadar EDR
DataStage on Cloud Pak for Data
Dell EMC OpenManage Enterprise Services
IBM Cloud Pak for Watson AIOps
IBM Sterling Order Management
SUSE Manager Server
SUSE Linux Enterprise Module for SUSE Manager Server
Ubuntu
openEuler
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Oracle Hospitality Suite8
Voice Gateway
Cloud Pak for Security (CP4S)
IBM Qradar SIEM
Red Hat Single Sign-On
IBM Security Guardium

How to mitigate CVE-2021-21290

Install updates from vendor's website.

Netty - update to 4.1.59
qpid-proton (Red Hat package) - addressed in versions 0.33.0-6.el7_9, 0.33.0-8.el8
pulpcore-selinux (Red Hat package) - update to 1.2.7-1.el7pc
Log Analysis - update to 1.3.8
IBM Operations Analytics Predictive Insights - update to 1.3.6.8
AMQ Streams - update to 1.8.0
Planning Analytics Local - update to 2.0.1
tfm-rubygem-katello (Red Hat package) - update to 4.1.1.42-1.el7sat
Security QRadar EDR - update to 3.12.15
netty (Debian package) - update to 1:4.1.33-1+deb10u2
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.8, 4.8.9, 5.1.1, 5.1.2, 5.1.3
DataStage on Cloud Pak for Data - update to 4.8.5
satellite (Red Hat package) - update to 6.10.2-1.el7sat
AMQ Broker - addressed in versions 7.8.2, 7.9.0
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.12.1
Red Hat Decision Manager - update to 7.12.1
Autodesk Infraworks - addressed in versions 2021.2 Hotfix 9, 2023.1 Hotfix 1
libnetty-java (Ubuntu package) - addressed in versions Ubuntu Pro, 1:4.1.48-4+deb11u1build0.22.04.1, 1:4.1.48-5ubuntu0.1
Voice Gateway - addressed in versions 1.0.8.2, 1.0.8.6
Dell EMC OpenManage Enterprise Services - update to 1.2
Netcool Operations Insight - update to 1.6.6
Cloud Pak for Security (CP4S) - update to 1.10.12.0
IBM Cloud Transformation Advisor - update to 3.3.1
IBM Cloud Pak for Watson AIOps - update to 3.6.1
netty-help - addressed in versions 4.1.13-10, 4.1.13-20, 4.1.13-23
netty - addressed in versions 4.1.13-10, 4.1.13-20, 4.1.13-23
netty - addressed in versions 4.1.44.Final-150200.3.4.2, 4.1.44.Final-150300.4.3.2, 4.1.44.Final-150400.3.3.2
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.6.2
Dell Secure Connect Gateway - update to 5.0
Red Hat Satellite - update to 6.10.2
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 9, 7.5.0 Update Pack 5
Red Hat Single Sign-On - update to 7.4.7
Fuse - update to 7.10.0
IBM Sterling Order Management - update to 10.0.0.29
IBM Spectrum Protect Plus - update to 10.1.6.4
IBM Security Guardium - addressed in versions 11.0p360, 11.0p430

External References

Related Security Bulletins