First published: Tue Mar 30 2021(Updated: )
### Impact The content-length header is not correctly validated if the request only use a single Http2HeaderFrame with the endStream set to to true. This could lead to request smuggling if the request is proxied to a remote peer and translated to HTTP/1.1 This is a followup of https://github.com/netty/netty/security/advisories/GHSA-wm47-8v5p-wjpj which did miss to fix this one case. ### Patches This was fixed as part of 4.1.61.Final ### Workarounds Validation can be done by the user before proxy the request by validating the header.
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
maven/io.netty:netty | <4.0.0 | |
maven/org.jboss.netty:netty | <4.0.0 | |
maven/io.netty:netty-codec-http2 | >=4.0.0<4.1.61.Final | 4.1.61.Final |
redhat/qpid-proton | <0:0.33.0-6.el7_9 | 0:0.33.0-6.el7_9 |
redhat/qpid-proton | <0:0.33.0-8.el8 | 0:0.33.0-8.el8 |
redhat/eap7-elytron-web | <0:1.6.3-1.Final_redhat_00001.1.el6ea | 0:1.6.3-1.Final_redhat_00001.1.el6ea |
redhat/eap7-hal-console | <0:3.2.15-1.Final_redhat_00001.1.el6ea | 0:3.2.15-1.Final_redhat_00001.1.el6ea |
redhat/eap7-hibernate | <0:5.3.20-3.SP1_redhat_00001.1.el6ea | 0:5.3.20-3.SP1_redhat_00001.1.el6ea |
redhat/eap7-infinispan | <0:9.4.23-1.Final_redhat_00001.1.el6ea | 0:9.4.23-1.Final_redhat_00001.1.el6ea |
redhat/eap7-ironjacamar | <0:1.4.33-1.Final_redhat_00001.1.el6ea | 0:1.4.33-1.Final_redhat_00001.1.el6ea |
redhat/eap7-jberet | <0:1.3.8-1.Final_redhat_00001.1.el6ea | 0:1.3.8-1.Final_redhat_00001.1.el6ea |
redhat/eap7-jboss-remoting | <0:5.0.23-1.Final_redhat_00001.1.el6ea | 0:5.0.23-1.Final_redhat_00001.1.el6ea |
redhat/eap7-jboss-server-migration | <0:1.7.2-7.Final_redhat_00008.1.el6ea | 0:1.7.2-7.Final_redhat_00008.1.el6ea |
redhat/eap7-netty | <0:4.1.63-1.Final_redhat_00001.1.el6ea | 0:4.1.63-1.Final_redhat_00001.1.el6ea |
redhat/eap7-undertow | <0:2.0.38-1.SP1_redhat_00001.1.el6ea | 0:2.0.38-1.SP1_redhat_00001.1.el6ea |
redhat/eap7-wildfly | <0:7.3.8-1.GA_redhat_00001.1.el6ea | 0:7.3.8-1.GA_redhat_00001.1.el6ea |
redhat/eap7-wildfly-elytron | <0:1.10.13-1.Final_redhat_00001.1.el6ea | 0:1.10.13-1.Final_redhat_00001.1.el6ea |
redhat/eap7-wildfly-http-client | <0:1.0.28-1.Final_redhat_00001.1.el6ea | 0:1.0.28-1.Final_redhat_00001.1.el6ea |
redhat/eap7-elytron-web | <0:1.6.3-1.Final_redhat_00001.1.el7ea | 0:1.6.3-1.Final_redhat_00001.1.el7ea |
redhat/eap7-hal-console | <0:3.2.15-1.Final_redhat_00001.1.el7ea | 0:3.2.15-1.Final_redhat_00001.1.el7ea |
redhat/eap7-hibernate | <0:5.3.20-3.SP1_redhat_00001.1.el7ea | 0:5.3.20-3.SP1_redhat_00001.1.el7ea |
redhat/eap7-infinispan | <0:9.4.23-1.Final_redhat_00001.1.el7ea | 0:9.4.23-1.Final_redhat_00001.1.el7ea |
redhat/eap7-ironjacamar | <0:1.4.33-1.Final_redhat_00001.1.el7ea | 0:1.4.33-1.Final_redhat_00001.1.el7ea |
redhat/eap7-jberet | <0:1.3.8-1.Final_redhat_00001.1.el7ea | 0:1.3.8-1.Final_redhat_00001.1.el7ea |
redhat/eap7-jboss-remoting | <0:5.0.23-1.Final_redhat_00001.1.el7ea | 0:5.0.23-1.Final_redhat_00001.1.el7ea |
redhat/eap7-jboss-server-migration | <0:1.7.2-7.Final_redhat_00008.1.el7ea | 0:1.7.2-7.Final_redhat_00008.1.el7ea |
redhat/eap7-netty | <0:4.1.63-1.Final_redhat_00001.1.el7ea | 0:4.1.63-1.Final_redhat_00001.1.el7ea |
redhat/eap7-undertow | <0:2.0.38-1.SP1_redhat_00001.1.el7ea | 0:2.0.38-1.SP1_redhat_00001.1.el7ea |
redhat/eap7-wildfly | <0:7.3.8-1.GA_redhat_00001.1.el7ea | 0:7.3.8-1.GA_redhat_00001.1.el7ea |
redhat/eap7-wildfly-elytron | <0:1.10.13-1.Final_redhat_00001.1.el7ea | 0:1.10.13-1.Final_redhat_00001.1.el7ea |
redhat/eap7-wildfly-http-client | <0:1.0.28-1.Final_redhat_00001.1.el7ea | 0:1.0.28-1.Final_redhat_00001.1.el7ea |
redhat/eap7-elytron-web | <0:1.6.3-1.Final_redhat_00001.1.el8ea | 0:1.6.3-1.Final_redhat_00001.1.el8ea |
redhat/eap7-hal-console | <0:3.2.15-1.Final_redhat_00001.1.el8ea | 0:3.2.15-1.Final_redhat_00001.1.el8ea |
redhat/eap7-hibernate | <0:5.3.20-3.SP1_redhat_00001.1.el8ea | 0:5.3.20-3.SP1_redhat_00001.1.el8ea |
redhat/eap7-infinispan | <0:9.4.23-1.Final_redhat_00001.1.el8ea | 0:9.4.23-1.Final_redhat_00001.1.el8ea |
redhat/eap7-ironjacamar | <0:1.4.33-1.Final_redhat_00001.1.el8ea | 0:1.4.33-1.Final_redhat_00001.1.el8ea |
redhat/eap7-jberet | <0:1.3.8-1.Final_redhat_00001.1.el8ea | 0:1.3.8-1.Final_redhat_00001.1.el8ea |
redhat/eap7-jboss-remoting | <0:5.0.23-1.Final_redhat_00001.1.el8ea | 0:5.0.23-1.Final_redhat_00001.1.el8ea |
redhat/eap7-jboss-server-migration | <0:1.7.2-7.Final_redhat_00008.1.el8ea | 0:1.7.2-7.Final_redhat_00008.1.el8ea |
redhat/eap7-netty | <0:4.1.63-1.Final_redhat_00001.1.el8ea | 0:4.1.63-1.Final_redhat_00001.1.el8ea |
redhat/eap7-undertow | <0:2.0.38-1.SP1_redhat_00001.1.el8ea | 0:2.0.38-1.SP1_redhat_00001.1.el8ea |
redhat/eap7-wildfly | <0:7.3.8-1.GA_redhat_00001.1.el8ea | 0:7.3.8-1.GA_redhat_00001.1.el8ea |
redhat/eap7-wildfly-elytron | <0:1.10.13-1.Final_redhat_00001.1.el8ea | 0:1.10.13-1.Final_redhat_00001.1.el8ea |
redhat/eap7-wildfly-http-client | <0:1.0.28-1.Final_redhat_00001.1.el8ea | 0:1.0.28-1.Final_redhat_00001.1.el8ea |
redhat/candlepin | <0:4.1.13-1.el7 | 0:4.1.13-1.el7 |
redhat/candlepin | <0:4.1.13-1.el8 | 0:4.1.13-1.el8 |
redhat/netty-codec-http | <4.1.61. | 4.1.61. |
Netty Netty | <4.1.61 | |
Debian Debian Linux | =10.0 | |
NetApp OnCommand API Services | ||
NetApp OnCommand Workflow Automation | ||
Oracle Banking Corporate Lending Process Management | =14.2.0 | |
Oracle Banking Corporate Lending Process Management | =14.3.0 | |
Oracle Banking Corporate Lending Process Management | =14.5.0 | |
Oracle Banking Credit Facilities Process Management | =14.2.0 | |
Oracle Banking Credit Facilities Process Management | =14.3.0 | |
Oracle Banking Credit Facilities Process Management | =14.5.0 | |
Oracle Banking Trade Finance Process Management | =14.2.0 | |
Oracle Banking Trade Finance Process Management | =14.3.0 | |
Oracle Banking Trade Finance Process Management | =14.5.0 | |
Oracle Coherence | =12.2.1.4.0 | |
Oracle Coherence | =14.1.1.0.0 | |
Oracle Communications Brm - Elastic Charging Engine | =12.0.0.3 | |
Oracle Communications Cloud Native Core Console | =1.7.0 | |
Oracle Communications Cloud Native Core Policy | =1.14.0 | |
Oracle Communications Design Studio | =7.4.2.0.0 | |
Oracle Communications Messaging Server | =8.1 | |
Oracle Helidon | =1.4.10 | |
Oracle Helidon | =2.4.0 | |
Oracle Jd Edwards Enterpriseone Tools | <9.2.6.3 | |
Oracle Nosql Database | <21.1.12 | |
Oracle Primavera Gateway | >=17.12.0<=17.12.11 | |
Oracle Primavera Gateway | >=18.8.0<=18.8.11 | |
Oracle Primavera Gateway | >=19.12.0<=19.12.10 | |
Quarkus Quarkus | <=1.13.7 | |
debian/netty | 1:4.1.48-4+deb11u2 1:4.1.48-7+deb12u1 1:4.1.48-10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)