Cleartext storage of sensitive information in Netty - CVE-2021-21290
Published: April 1, 2021 / Updated: February 11, 2025
Vulnerability identifier: #VU51835
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-21290
CWE-ID: CWE-312
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to insecure usage of temporary files in AbstractDiskHttpData method in Netty. The application stores sensitive information in temporary file that has insecure permissions. A local user can view application's temporary file and gain access to potentially sensitive data.Affected software
Netty
IBM Observability with Instana
Log Analysis
IBM Operations Analytics Predictive Insights
AMQ Clients
IBM Watson Knowledge Catalog in Cloud Pak for Data
Oracle Communications Design Studio
Red Hat Decision Manager
Autodesk Infraworks
Netcool Operations Insight
IBM Cloud Transformation Advisor
IBM Watson Assistant for IBM Cloud Pak for Data
Dell Secure Connect Gateway
Red Hat Satellite
IBM Spectrum Protect Plus
qpid-proton (Red Hat package)
pulpcore-selinux (Red Hat package)
tfm-rubygem-katello (Red Hat package)
netty (Debian package)
satellite (Red Hat package)
libnetty-java (Ubuntu package)
netty-help
netty
AMQ Streams
AMQ Broker
Fuse
Planning Analytics Local
PeopleSoft Enterprise PeopleTools
IBM Cloud Private
Security QRadar EDR
DataStage on Cloud Pak for Data
Dell EMC OpenManage Enterprise Services
IBM Cloud Pak for Watson AIOps
IBM Sterling Order Management
SUSE Manager Server
SUSE Linux Enterprise Module for SUSE Manager Server
Ubuntu
openEuler
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Oracle Hospitality Suite8
Voice Gateway
Cloud Pak for Security (CP4S)
IBM Qradar SIEM
Red Hat Single Sign-On
IBM Security Guardium
IBM Observability with Instana
Log Analysis
IBM Operations Analytics Predictive Insights
AMQ Clients
IBM Watson Knowledge Catalog in Cloud Pak for Data
Oracle Communications Design Studio
Red Hat Decision Manager
Autodesk Infraworks
Netcool Operations Insight
IBM Cloud Transformation Advisor
IBM Watson Assistant for IBM Cloud Pak for Data
Dell Secure Connect Gateway
Red Hat Satellite
IBM Spectrum Protect Plus
qpid-proton (Red Hat package)
pulpcore-selinux (Red Hat package)
tfm-rubygem-katello (Red Hat package)
netty (Debian package)
satellite (Red Hat package)
libnetty-java (Ubuntu package)
netty-help
netty
AMQ Streams
AMQ Broker
Fuse
Planning Analytics Local
PeopleSoft Enterprise PeopleTools
IBM Cloud Private
Security QRadar EDR
DataStage on Cloud Pak for Data
Dell EMC OpenManage Enterprise Services
IBM Cloud Pak for Watson AIOps
IBM Sterling Order Management
SUSE Manager Server
SUSE Linux Enterprise Module for SUSE Manager Server
Ubuntu
openEuler
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Oracle Hospitality Suite8
Voice Gateway
Cloud Pak for Security (CP4S)
IBM Qradar SIEM
Red Hat Single Sign-On
IBM Security Guardium
How to mitigate CVE-2021-21290
Install updates from vendor's website.
Netty - update to 4.1.59
qpid-proton (Red Hat package) - addressed in versions 0.33.0-6.el7_9, 0.33.0-8.el8
pulpcore-selinux (Red Hat package) - update to 1.2.7-1.el7pc
Log Analysis - update to 1.3.8
IBM Operations Analytics Predictive Insights - update to 1.3.6.8
AMQ Streams - update to 1.8.0
Planning Analytics Local - update to 2.0.1
tfm-rubygem-katello (Red Hat package) - update to 4.1.1.42-1.el7sat
Security QRadar EDR - update to 3.12.15
netty (Debian package) - update to 1:4.1.33-1+deb10u2
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.8, 4.8.9, 5.1.1, 5.1.2, 5.1.3
DataStage on Cloud Pak for Data - update to 4.8.5
satellite (Red Hat package) - update to 6.10.2-1.el7sat
AMQ Broker - addressed in versions 7.8.2, 7.9.0
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.12.1
Red Hat Decision Manager - update to 7.12.1
Autodesk Infraworks - addressed in versions 2021.2 Hotfix 9, 2023.1 Hotfix 1
libnetty-java (Ubuntu package) - addressed in versions Ubuntu Pro, 1:4.1.48-4+deb11u1build0.22.04.1, 1:4.1.48-5ubuntu0.1
Voice Gateway - addressed in versions 1.0.8.2, 1.0.8.6
Dell EMC OpenManage Enterprise Services - update to 1.2
Netcool Operations Insight - update to 1.6.6
Cloud Pak for Security (CP4S) - update to 1.10.12.0
IBM Cloud Transformation Advisor - update to 3.3.1
IBM Cloud Pak for Watson AIOps - update to 3.6.1
netty-help - addressed in versions 4.1.13-10, 4.1.13-20, 4.1.13-23
netty - addressed in versions 4.1.13-10, 4.1.13-20, 4.1.13-23
netty - addressed in versions 4.1.44.Final-150200.3.4.2, 4.1.44.Final-150300.4.3.2, 4.1.44.Final-150400.3.3.2
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.6.2
Dell Secure Connect Gateway - update to 5.0
Red Hat Satellite - update to 6.10.2
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 9, 7.5.0 Update Pack 5
Red Hat Single Sign-On - update to 7.4.7
Fuse - update to 7.10.0
IBM Sterling Order Management - update to 10.0.0.29
IBM Spectrum Protect Plus - update to 10.1.6.4
IBM Security Guardium - addressed in versions 11.0p360, 11.0p430
qpid-proton (Red Hat package) - addressed in versions 0.33.0-6.el7_9, 0.33.0-8.el8
pulpcore-selinux (Red Hat package) - update to 1.2.7-1.el7pc
Log Analysis - update to 1.3.8
IBM Operations Analytics Predictive Insights - update to 1.3.6.8
AMQ Streams - update to 1.8.0
Planning Analytics Local - update to 2.0.1
tfm-rubygem-katello (Red Hat package) - update to 4.1.1.42-1.el7sat
Security QRadar EDR - update to 3.12.15
netty (Debian package) - update to 1:4.1.33-1+deb10u2
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.8, 4.8.9, 5.1.1, 5.1.2, 5.1.3
DataStage on Cloud Pak for Data - update to 4.8.5
satellite (Red Hat package) - update to 6.10.2-1.el7sat
AMQ Broker - addressed in versions 7.8.2, 7.9.0
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.12.1
Red Hat Decision Manager - update to 7.12.1
Autodesk Infraworks - addressed in versions 2021.2 Hotfix 9, 2023.1 Hotfix 1
libnetty-java (Ubuntu package) - addressed in versions Ubuntu Pro, 1:4.1.48-4+deb11u1build0.22.04.1, 1:4.1.48-5ubuntu0.1
Voice Gateway - addressed in versions 1.0.8.2, 1.0.8.6
Dell EMC OpenManage Enterprise Services - update to 1.2
Netcool Operations Insight - update to 1.6.6
Cloud Pak for Security (CP4S) - update to 1.10.12.0
IBM Cloud Transformation Advisor - update to 3.3.1
IBM Cloud Pak for Watson AIOps - update to 3.6.1
netty-help - addressed in versions 4.1.13-10, 4.1.13-20, 4.1.13-23
netty - addressed in versions 4.1.13-10, 4.1.13-20, 4.1.13-23
netty - addressed in versions 4.1.44.Final-150200.3.4.2, 4.1.44.Final-150300.4.3.2, 4.1.44.Final-150400.3.3.2
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.6.2
Dell Secure Connect Gateway - update to 5.0
Red Hat Satellite - update to 6.10.2
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 9, 7.5.0 Update Pack 5
Red Hat Single Sign-On - update to 7.4.7
Fuse - update to 7.10.0
IBM Sterling Order Management - update to 10.0.0.29
IBM Spectrum Protect Plus - update to 10.1.6.4
IBM Security Guardium - addressed in versions 11.0p360, 11.0p430
External References
- https://github.com/netty/netty/commit/c735357bf29d07856ad171c6611a2e1a0e0000ec
- https://github.com/netty/netty/security/advisories/GHSA-5mcr-gq6c-3hq2
- https://lists.apache.org/thread.html/r0053443ce19ff125981559f8c51cf66e3ab4350f47812b8cf0733a05@%3Cdev.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r02e467123d45006a1dda20a38349e9c74c3a4b53e2e07be0939ecb3f@%3Cdev.ranger.apache.org%3E
- https://lists.apache.org/thread.html/r0857b613604c696bf9743f0af047360baaded48b1c75cf6945a083c5@%3Cjira.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r10308b625e49d4e9491d7e079606ca0df2f0a4d828f1ad1da64ba47b@%3Cjira.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r1908a34b9cc7120e5c19968a116ddbcffea5e9deb76c2be4fa461904@%3Cdev.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r2748097ea4b774292539cf3de6e3b267fc7a88d6c8ec40f4e2e87bd4@%3Cdev.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r2fda4dab73097051977f2ab818f75e04fbcb15bb1003c8530eac1059@%3Cjira.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r326ec431f06eab7cb7113a7a338e59731b8d556d05258457f12bac1b@%3Cdev.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r4efed2c501681cb2e8d629da16e48d9eac429624fd4c9a8c6b8e7020@%3Cdev.tinkerpop.apache.org%3E
- https://lists.apache.org/thread.html/r59bac5c09f7a4179b9e2460e8f41c278aaf3b9a21cc23678eb893e41@%3Cjira.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r5bf303d7c04da78f276765da08559fdc62420f1df539b277ca31f63b@%3Cissues.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r5e4a540089760c8ecc2c411309d74264f1dad634ad93ad583ca16214@%3Ccommits.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r5e66e286afb5506cdfe9bbf68a323e8d09614f6d1ddc806ed0224700@%3Cjira.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r71dbb66747ff537640bb91eb0b2b24edef21ac07728097016f58b01f@%3Ccommits.kafka.apache.org%3E
- https://lists.apache.org/thread.html/r743149dcc8db1de473e6bff0b3ddf10140a7357bc2add75f7d1fbb12@%3Cdev.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/r790c2926efcd062067eb18fde2486527596d7275381cfaff2f7b3890@%3Cissues.bookkeeper.apache.org%3E
- https://lists.apache.org/thread.html/r7bb3cdc192e9a6f863d3ea05422f09fa1ae2b88d4663e63696ee7ef5@%3Cdev.ranger.apache.org%3E
- https://lists.apache.org/thread.html/r9924ef9357537722b28d04c98a189750b80694a19754e5057c34ca48@%3Ccommits.pulsar.apache.org%3E
- https://lists.apache.org/thread.html/ra0fc2b4553dd7aaf75febb61052b7f1243ac3a180a71c01f29093013@%3Cjira.kafka.apache.org%3E
- https://lists.apache.org/thread.html/ra503756ced78fdc2136bd33e87cb7553028645b261b1f5c6186a121e@%3Cjira.kafka.apache.org%3E
- https://lists.apache.org/thread.html/rb06c1e766aa45ee422e8261a8249b561784186483e8f742ea627bda4@%3Cdev.kafka.apache.org%3E
- https://lists.apache.org/thread.html/rb51d6202ff1a773f96eaa694b7da4ad3f44922c40b3d4e1a19c2f325@%3Ccommits.pulsar.apache.org%3E
- https://lists.apache.org/thread.html/rb592033a2462548d061a83ac9449c5ff66098751748fcd1e2d008233@%3Cissues.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/rc0087125cb15b4b78e44000f841cd37fefedfda942fd7ddf3ad1b528@%3Cissues.zookeeper.apache.org%3E
- https://lists.apache.org/thread.html/rc488f80094872ad925f0c73d283d4c00d32def81977438e27a3dc2bb@%3Cjira.kafka.apache.org%3E
- https://lists.apache.org/thread.html/rcd163e421273e8dca1c71ea298dce3dd11b41d51c3a812e0394e6a5d@%3Ccommits.pulsar.apache.org%3E
- https://lists.apache.org/thread.html/rdba4f78ac55f803893a1a2265181595e79e3aa027e2e651dfba98c18@%3Cjira.kafka.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2021/02/msg00016.html
Related Security Bulletins
- Information disclosure in Netty
- Debian update for netty
- Red Hat AMQ Clients 2.9.1 update for netty
- Multiple vulnerabilities in Red Hat AMQ Broker
- Cleartext storage of sensitive information in Oracle Communications Design Studio
- Cleartext storage of sensitive information in Oracle Hospitality Suite8
- Multiple vulnerabilities in PeopleSoft Enterprise PeopleTools
- Multiple vulnerabilities in Red Hat AMQ Streams
- Multiple vulnerabilities in Red Hat AMQ Broker
- IBM Cloud Private update for Netty
- Information disclosure in Red Hat Satellite
- Multiple vulnerabilities in Red Hat Process Automation Manager
- Multiple vulnerabilities in Red Hat Decision Manager
- Multiple vulnerabilities in IBM Planning Analytics Local
- Multiple vulnerabilities in Dell EMC SupportAssist Enterprise
- SUSE update for netty
- Multiple vulnerabilities in IBM Sterling Order Management
- SUSE update for netty
- SUSE update for netty
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in IBM Voice Gateway
- Cleartext storage of sensitive information in IBM Watson Assistant for IBM Cloud Pak for Data
- Multiple vulnerabilities in Autodesk InfraWorks
- Ubuntu update for netty
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM Observability with Instana (OnPrem)
- openEuler 20.03 LTS SP1 update for netty
- Multiple vulnerabilities in IBM Operations Analytics - Log Analysis
- Multiple vulnerabilities in IBM Operations Analytics Predictive Insights
- Multiple vulnerabilities in Red Hat Single Sign-On 7.4
- Multiple vulnerabilities in Fuse 7.10
- Multiple vulnerabilities in IBM Spectrum Protect Plus
- Multiple vulnerabilities in IBM Security Guardium
- Multiple vulnerabilities in IBM Security QRadar EDR
- Multiple vulnerabilities in IBM DataStage on Cloud Pak for Data
- Multiple vulnerabilities in IBM Watson Knowledge Catalog
- openEuler 22.03 LTS SP4 update for netty
- openEuler 22.03 LTS SP3 update for netty
- openEuler 20.03 LTS SP4 update for netty
- openEuler 24.03 LTS SP2 update for netty
- openEuler 24.03 LTS SP1 update for netty
- openEuler 24.03 LTS update for netty