REDHAT-BUG-2505975: High severity Netty Netty vulnerability
Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, any caller that can deliver bytes to a Netty channel pipeline containing XmlDecoder can send XML with a DOCTYPE declaration to an AsyncXMLInputFactory instantiated with no security configuration, leaving DTD and entity handling active depending on Aalto XML async parser behavior and creating conditional XML external entity risk. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Aalto XML async parser (Netty XmlDecoder / AsyncXMLInputFactory)to a version that resolves this vulnerability.Fixed in 4.1.136.Final - Upgrade
Upgrade
Aalto XML async parser (Netty XmlDecoder / AsyncXMLInputFactory)to a version that resolves this vulnerability.Fixed in 4.2.16.Final
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2505975?
The severity of REDHAT-BUG-2505975 is classified as high, with a score of 7.
What does REDHAT-BUG-2505975 affect?
REDHAT-BUG-2505975 affects Netty versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final.
How do I fix REDHAT-BUG-2505975?
To fix REDHAT-BUG-2505975, upgrade to a version of Netty that is not affected by this vulnerability.
What is the nature of the vulnerability in REDHAT-BUG-2505975?
The vulnerability in REDHAT-BUG-2505975 allows attackers to send malicious XML with a DOCTYPE declaration to a Netty channel pipeline containing XmlDecoder.
What potential impact does REDHAT-BUG-2505975 have on systems?
The impact of REDHAT-BUG-2505975 can potentially lead to XML External Entity (XXE) attacks, compromising the security of the application.