First published: Wed Jul 07 2021(Updated: )
This release of Red Hat build of Eclipse Vert.x 4.1.0 includes security updates, bug fixes, and enhancements. For more information, see the release notes listed in the References section.<br>Security Fix(es):<br><li> netty: Request smuggling via content-length header (CVE-2021-21409)</li> <li> apache-commons-io: Limited path traversal in Apache Commons IO 2.2 to 2.6 (CVE-2021-29425)</li> For more details about the security issues and their impact, the CVSS score, acknowledgements, and other related information, see the CVE pages listed in the References section.
Affected Software | Affected Version | How to fix |
---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2021:2465 is classified as moderate.
To fix RHSA-2021:2465, you should update to the latest available version of Red Hat build of Eclipse Vert.x.
The main issue addressed in RHSA-2021:2465 is a request smuggling vulnerability via content-length headers, tracked as CVE-2021-21409.
RHSA-2021:2465 affects specific versions of Red Hat build of Eclipse Vert.x prior to the security updates.
More details about RHSA-2021:2465 can typically be found in the release notes associated with the advisory.