6.5
CVSSv3

CVE-2021-43797

Published: 09/12/2021 Updated: 24/02/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. Netty prior to version 4.1.71.Final skips control chars when they are present at the beginning / end of the header name. It should instead fail fast as these are not allowed by the spec and could lead to HTTP request smuggling. Failing to do the validation might cause netty to "sanitize" header names before it forward these to another remote system when used as proxy. This remote system can't see the invalid usage anymore, and therefore does not do the validation itself. Users should upgrade to version 4.1.71.Final.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

netty netty

quarkus quarkus

netapp snapcenter -

netapp oncommand workflow automation -

oracle banking platform 2.6.2

oracle peoplesoft enterprise peopletools 8.58

oracle coherence 12.2.1.4.0

oracle coherence 14.1.1.0.0

oracle peoplesoft enterprise peopletools 8.59

oracle communications cloud native core security edge protection proxy 1.7.0

oracle banking party management 2.7.0

oracle communications design studio 7.4.2

oracle communications cloud native core policy 1.15.0

oracle communications cloud native core unified data repository 1.15.0

oracle communications cloud native core network slice selection function 1.8.0

oracle communications cloud native core binding support function 1.11.0

oracle helidon 2.4.0

oracle helidon 1.4.10

oracle communications instant messaging server 8.1

oracle banking deposits and lines of credit servicing 2.7

debian debian linux 10.0

debian debian linux 11.0

Vendor Advisories

Debian Bug report logs - #1001437 netty: CVE-2021-43797: HTTP fails to validate against control chars in header names which may lead to HTTP request smuggling Package: src:netty; Maintainer for src:netty is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@deb ...
Several out-of-memory, stack overflow or HTTP request smuggling vulnerabilities have been discovered in Netty, a Java NIO client/server socket framework, which may allow attackers to cause a denial of service or bypass restrictions when used as a proxy For the stable distribution (bullseye), these problems have been fixed in version 1:4148-4+deb ...
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients Netty prior to version 4171Final skips control chars when they are present at the beginning / end of the header name It should instead fail fast as these are not allowed by the spec and coul ...
Synopsis Moderate: Red Hat AMQ Streams 210 release and security update Type/Severity Security Advisory: Moderate Topic Red Hat AMQ Streams 210 is now available from the Red Hat Customer PortalRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, wh ...
Synopsis Moderate: Red Hat Single Sign-On 753 security update on RHEL 7 Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic New Red Hat Single Sign-On 753 packages are now available for Red Hat Enterprise Linux 7Red Hat P ...
Synopsis Moderate: Red Hat JBoss Enterprise Application Platform 745 security update Type/Severity Security Advisory: Moderate Topic A security update is now available for Red Hat JBoss Enterprise Application Platform 74Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring S ...
Synopsis Moderate: Red Hat JBoss Enterprise Application Platform 745 security update on RHEL 8 Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic A security update is now available for Red Hat JBoss Enterprise Application P ...
Synopsis Moderate: Red Hat JBoss Enterprise Application Platform 745 security update on RHEL 7 Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic A security update is now available for Red Hat JBoss Enterprise Application P ...
Synopsis Moderate: Red Hat Process Automation Manager 7130 security update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat Process Automation ManagerRed Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scoring System (CVSS) base score, which gives a ...
Synopsis Moderate: Red Hat OpenShift Logging Security and Bug update Release 537 Type/Severity Security Advisory: Moderate Topic Openshift Logging Bug Fix Release (537)Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed seve ...
Synopsis Moderate: Red Hat OpenShift Logging Security and Bug update Release 541 Type/Severity Security Advisory: Moderate Topic Logging Subsystem 541 - Red Hat OpenShiftRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed se ...
Synopsis Moderate: Red Hat Single Sign-On 761 security update Type/Severity Security Advisory: Moderate Topic A security update is now available for Red Hat Single Sign-On 76 from the Customer PortalRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base sco ...
Synopsis Moderate: Red Hat Single Sign-On 753 security update Type/Severity Security Advisory: Moderate Topic A security update is now available for Red Hat Single Sign-On 75 from the Customer PortalRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base sco ...
Synopsis Moderate: Red Hat Single Sign-On 761 security update on RHEL 9 Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic New Red Hat Single Sign-On 761 packages are now available for Red Hat Enterprise Linux 9Red Hat P ...
Synopsis Moderate: Red Hat Single Sign-On 761 security update on RHEL 8 Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic New Red Hat Single Sign-On 761 packages are now available for Red Hat Enterprise Linux 8Red Hat P ...
Synopsis Moderate: Red Hat Single Sign-On 761 security update on RHEL 7 Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic New Red Hat Single Sign-On 761 packages are now available for Red Hat Enterprise Linux 7Red Hat P ...
Synopsis Moderate: Openshift Logging Security and Bug update Release (5210) Type/Severity Security Advisory: Moderate Topic Openshift Logging Bug Fix Release (5210)Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity ...
Synopsis Moderate: Red Hat build of Quarkus 275 release and security update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat build of QuarkusRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, which gives a det ...
Synopsis Important: Red Hat AMQ Broker 7100 release and security update Type/Severity Security Advisory: Important Topic Red Hat AMQ Broker 7100 is now available from the Red Hat Customer PortalRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, ...
Synopsis Moderate: Satellite 611 Release Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update is now available for Red Hat Satellite 611 Description Red Hat Satellite is a systems management tool for Linux-basedin ...
Synopsis Moderate: Red Hat Single Sign-On 753 security update on RHEL 8 Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic New Red Hat Single Sign-On 753 packages are now available for Red Hat Enterprise Linux 8Red Hat P ...
Synopsis Moderate: Red Hat Data Grid 830 security update Type/Severity Security Advisory: Moderate Topic An update for Red Hat Data Grid is now availableRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is ...
Synopsis Important: Red Hat Fuse 7110 release and security update Type/Severity Security Advisory: Important Topic A minor version update (from 710 to 711) is now available for Red Hat Fuse The purpose of this text-only errata is to inform you about the security issues fixed in this releaseRed Hat Product Security has rated this update ...
Multiple vulnerabilities have been found in Hitachi Ops Center Common Services CVE-2020-36518, CVE-2021-43797, CVE-2022-0839, CVE-2022-22968 Affected products and versions are listed below Please upgrade your version to the appropriate version ...