CVE-2021-21409: Possible request smuggling in HTTP/2 due missing validation of content-length
Impact The content-length header is not correctly validated if the request only use a single Http2HeaderFrame with the endStream set to to true. This could lead to request smuggling if the request is proxied to a remote peer and translated to HTTP/1.1
This is a followup of https://github.com/netty/netty/security/advisories/GHSA-wm47-8v5p-wjpj which did miss to fix this one case.
Patches This was fixed as part of 4.1.61.Final
Workarounds Validation can be done by the user before proxy the request by validating the header.
Other sources
A flaw was found in Netty. There is an issue where the content-length header is not validated correctly if the request uses a single Http2HeaderFrame with the endstream set to true. This flaw leads to request smuggling if the request is proxied to a remote peer and translated to HTTP/1.1. The highest threat from this vulnerability is to integrity.
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.61.Final there is a vulnerability that enables request smuggling. The content-length header is not correctly validated if the request only uses a single Http2HeaderFrame with the endStream set to to true. This could lead to request smuggling if the request is proxied to a remote peer and translated to HTTP/1.1. This is a followup of GHSA-wm47-8v5p-wjpj/CVE-2021-21295 which did miss to fix this one case. This was fixed as part of 4.1.61.Final.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/io.netty:netty-codec-http2to a version that resolves this vulnerability.Fixed in 4.1.61.Final - Upgrade
Upgrade
redhat/qpid-protonto a version that resolves this vulnerability.Fixed in 0:0.33.0-6.el7_9 - Upgrade
Upgrade
redhat/qpid-protonto a version that resolves this vulnerability.Fixed in 0:0.33.0-8.el8 - Upgrade
Upgrade
redhat/eap7-elytron-webto a version that resolves this vulnerability.Fixed in 0:1.6.3-1.Final_redhat_00001.1.el6ea - Upgrade
Upgrade
redhat/eap7-hal-consoleto a version that resolves this vulnerability.Fixed in 0:3.2.15-1.Final_redhat_00001.1.el6ea - Upgrade
Upgrade
redhat/eap7-hibernateto a version that resolves this vulnerability.Fixed in 0:5.3.20-3.SP1_redhat_00001.1.el6ea - Upgrade
Upgrade
redhat/eap7-infinispanto a version that resolves this vulnerability.Fixed in 0:9.4.23-1.Final_redhat_00001.1.el6ea - Upgrade
Upgrade
redhat/eap7-ironjacamarto a version that resolves this vulnerability.Fixed in 0:1.4.33-1.Final_redhat_00001.1.el6ea - Upgrade
Upgrade
redhat/eap7-jberetto a version that resolves this vulnerability.Fixed in 0:1.3.8-1.Final_redhat_00001.1.el6ea - Upgrade
Upgrade
redhat/eap7-jboss-remotingto a version that resolves this vulnerability.Fixed in 0:5.0.23-1.Final_redhat_00001.1.el6ea - Upgrade
Upgrade
redhat/eap7-jboss-server-migrationto a version that resolves this vulnerability.Fixed in 0:1.7.2-7.Final_redhat_00008.1.el6ea - Upgrade
Upgrade
redhat/eap7-nettyto a version that resolves this vulnerability.Fixed in 0:4.1.63-1.Final_redhat_00001.1.el6ea - Upgrade
Upgrade
redhat/eap7-undertowto a version that resolves this vulnerability.Fixed in 0:2.0.38-1.SP1_redhat_00001.1.el6ea - Upgrade
Upgrade
redhat/eap7-wildflyto a version that resolves this vulnerability.Fixed in 0:7.3.8-1.GA_redhat_00001.1.el6ea - Upgrade
Upgrade
redhat/eap7-wildfly-elytronto a version that resolves this vulnerability.Fixed in 0:1.10.13-1.Final_redhat_00001.1.el6ea - Upgrade
Upgrade
redhat/eap7-wildfly-http-clientto a version that resolves this vulnerability.Fixed in 0:1.0.28-1.Final_redhat_00001.1.el6ea - Upgrade
Upgrade
redhat/eap7-elytron-webto a version that resolves this vulnerability.Fixed in 0:1.6.3-1.Final_redhat_00001.1.el7ea - Upgrade
Upgrade
redhat/eap7-hal-consoleto a version that resolves this vulnerability.Fixed in 0:3.2.15-1.Final_redhat_00001.1.el7ea - Upgrade
Upgrade
redhat/eap7-hibernateto a version that resolves this vulnerability.Fixed in 0:5.3.20-3.SP1_redhat_00001.1.el7ea - Upgrade
Upgrade
redhat/eap7-infinispanto a version that resolves this vulnerability.Fixed in 0:9.4.23-1.Final_redhat_00001.1.el7ea - Upgrade
Upgrade
redhat/eap7-ironjacamarto a version that resolves this vulnerability.Fixed in 0:1.4.33-1.Final_redhat_00001.1.el7ea - Upgrade
Upgrade
redhat/eap7-jberetto a version that resolves this vulnerability.Fixed in 0:1.3.8-1.Final_redhat_00001.1.el7ea - Upgrade
Upgrade
redhat/eap7-jboss-remotingto a version that resolves this vulnerability.Fixed in 0:5.0.23-1.Final_redhat_00001.1.el7ea - Upgrade
Upgrade
redhat/eap7-jboss-server-migrationto a version that resolves this vulnerability.Fixed in 0:1.7.2-7.Final_redhat_00008.1.el7ea - Upgrade
Upgrade
redhat/eap7-nettyto a version that resolves this vulnerability.Fixed in 0:4.1.63-1.Final_redhat_00001.1.el7ea - Upgrade
Upgrade
redhat/eap7-undertowto a version that resolves this vulnerability.Fixed in 0:2.0.38-1.SP1_redhat_00001.1.el7ea - Upgrade
Upgrade
redhat/eap7-wildflyto a version that resolves this vulnerability.Fixed in 0:7.3.8-1.GA_redhat_00001.1.el7ea - Upgrade
Upgrade
redhat/eap7-wildfly-elytronto a version that resolves this vulnerability.Fixed in 0:1.10.13-1.Final_redhat_00001.1.el7ea - Upgrade
Upgrade
redhat/eap7-wildfly-http-clientto a version that resolves this vulnerability.Fixed in 0:1.0.28-1.Final_redhat_00001.1.el7ea - Upgrade
Upgrade
redhat/eap7-elytron-webto a version that resolves this vulnerability.Fixed in 0:1.6.3-1.Final_redhat_00001.1.el8ea - Upgrade
Upgrade
redhat/eap7-hal-consoleto a version that resolves this vulnerability.Fixed in 0:3.2.15-1.Final_redhat_00001.1.el8ea - Upgrade
Upgrade
redhat/eap7-hibernateto a version that resolves this vulnerability.Fixed in 0:5.3.20-3.SP1_redhat_00001.1.el8ea - Upgrade
Upgrade
redhat/eap7-infinispanto a version that resolves this vulnerability.Fixed in 0:9.4.23-1.Final_redhat_00001.1.el8ea - Upgrade
Upgrade
redhat/eap7-ironjacamarto a version that resolves this vulnerability.Fixed in 0:1.4.33-1.Final_redhat_00001.1.el8ea - Upgrade
Upgrade
redhat/eap7-jberetto a version that resolves this vulnerability.Fixed in 0:1.3.8-1.Final_redhat_00001.1.el8ea - Upgrade
Upgrade
redhat/eap7-jboss-remotingto a version that resolves this vulnerability.Fixed in 0:5.0.23-1.Final_redhat_00001.1.el8ea - Upgrade
Upgrade
redhat/eap7-jboss-server-migrationto a version that resolves this vulnerability.Fixed in 0:1.7.2-7.Final_redhat_00008.1.el8ea - Upgrade
Upgrade
redhat/eap7-nettyto a version that resolves this vulnerability.Fixed in 0:4.1.63-1.Final_redhat_00001.1.el8ea - Upgrade
Upgrade
redhat/eap7-undertowto a version that resolves this vulnerability.Fixed in 0:2.0.38-1.SP1_redhat_00001.1.el8ea - Upgrade
Upgrade
redhat/eap7-wildflyto a version that resolves this vulnerability.Fixed in 0:7.3.8-1.GA_redhat_00001.1.el8ea - Upgrade
Upgrade
redhat/eap7-wildfly-elytronto a version that resolves this vulnerability.Fixed in 0:1.10.13-1.Final_redhat_00001.1.el8ea - Upgrade
Upgrade
redhat/eap7-wildfly-http-clientto a version that resolves this vulnerability.Fixed in 0:1.0.28-1.Final_redhat_00001.1.el8ea - Upgrade
Upgrade
redhat/candlepinto a version that resolves this vulnerability.Fixed in 0:4.1.13-1.el7 - Upgrade
Upgrade
redhat/candlepinto a version that resolves this vulnerability.Fixed in 0:4.1.13-1.el8 - Upgrade
Upgrade
debian/nettyto a version that resolves this vulnerability.Fixed in 1:4.1.48-4+deb11u2Fixed in 1:4.1.48-7+deb12u1Fixed in 1:4.1.48-10 - Upgrade
Upgrade
redhat/netty-codec-httpto a version that resolves this vulnerability.Fixed in 4.1.61. - Upgrade
Upgrade
io.netty:netty-codec-http2to a version that resolves this vulnerability.Fixed in 4.1.61.FinalPatch GHSA-f256-j965-7f32 - Compensating control
If you must proxy requests before upgrading, validate the HTTP content-length header yourself before proxying/forwarding the request, since content-length is not correctly validated when the request uses a single Http2HeaderFrame with endStream set to true (leading to possible request smuggling if translated to HTTP/1.1).
Event History
Parent advisories
This vulnerability appears in the following advisories.
- RHSA-2021:1511
- RHSA-2021:2696
- RHSA-2021:3660
- RHSA-2021:5128
- RHSA-2021:5127
- RHSA-2021:5129
- RHSA-2021:2689
- RHSA-2021:3700
- RHSA-2021:3225
- RHSA-2021:2139
- RHSA-2021:2755
- RHSA-2021:2692
- RHSA-2021:2693
- RHSA-2021:2694
- RHSA-2021:3658
- RHSA-2021:3656
- RHSA-2021:5134
- RHSA-2022:5498
- RHSA-2021:2965
- RHSA-2021:2465
- RHSA-2021:3880
- IBM-7277801
Frequently Asked Questions
What is the severity of CVE-2021-21409?
CVE-2021-21409 has been classified as a high severity vulnerability due to its potential for causing request smuggling.
How do I fix CVE-2021-21409?
To remediate CVE-2021-21409, update to Netty version 4.1.61.Final or later.
Which software is affected by CVE-2021-21409?
CVE-2021-21409 affects various Netty and JBoss packages, particularly those below version 4.1.61.
What type of vulnerability is CVE-2021-21409?
CVE-2021-21409 is a request smuggling vulnerability that arises from improper validation of the content-length header.
Can CVE-2021-21409 lead to further exploits?
Yes, CVE-2021-21409 can be exploited to facilitate other attacks if requests are proxied to remote servers.