6.5
CVSSv3

CVE-2022-41915

Published: 13/12/2022 Updated: 01/03/2023
CVSS v3 Base Score: 6.5 | Impact Score: 2.5 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Netty project is an event-driven asynchronous network application framework. Starting in version 4.1.83.Final and before 4.1.86.Final, when calling `DefaultHttpHeadesr.set` with an _iterator_ of values, header value validation was not performed, allowing malicious header values in the iterator to perform HTTP Response Splitting. This issue has been patched in version 4.1.86.Final. Integrators can work around the issue by changing the `DefaultHttpHeaders.set(CharSequence, Iterator<?>)` call, into a `remove()` call, and call `add()` in a loop over the iterator of values.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

netty netty

debian debian linux 10.0

debian debian linux 11.0

Vendor Advisories

Debian Bug report logs - #1027180 netty: CVE-2022-41915 CVE-2022-41881 Package: src:netty; Maintainer for src:netty is Debian Java Maintainers &lt;pkg-java-maintainers@listsaliothdebianorg&gt;; Reported by: Moritz Mühlenhoff &lt;jmm@inutilorg&gt; Date: Wed, 28 Dec 2022 22:51:04 UTC Severity: important Tags: security, upstre ...
Several out-of-memory, stack overflow or HTTP request smuggling vulnerabilities have been discovered in Netty, a Java NIO client/server socket framework, which may allow attackers to cause a denial of service or bypass restrictions when used as a proxy For the stable distribution (bullseye), these problems have been fixed in version 1:4148-4+deb ...
Hitachi Ops Center Analyzer contains the following vulnerabilities: CVE-2022-2047, CVE-2022-2048 Hitachi Ops Center Analyzer viewpoint contains the following vulnerability: CVE-2022-41862 Hitachi Ops Center Viewpoint contains the following vulnerabilities: CVE-2022-41862, CVE-2022-41881, CVE-2022-41915 Affected products and versions ...
Multiple vulnerabilities have been found in Hitachi Ops Center Common Services CVE-2020-8908, CVE-2020-14326, CVE-2020-25633, CVE-2020-36518, CVE-2021-20289, CVE-2021-21290, CVE-2021-46877, CVE-2022-3782, CVE-2022-4147, CVE-2022-40151, CVE-2022-40152, CVE-2022-41915, CVE-2022-41946, CVE-2022-41966, CVE-2023-0091, CVE-2023-1370, CVE-2023-28708 ...