Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-16869

Опубликовано: 26 сент. 2019
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling.

A flaw was found in Netty, where whitespace before the colon in HTTP headers is mishandled. This flaw allows an attacker to cause HTTP request smuggling.

Отчет

OpenShift Container Platform ships a vulnerable netty library as part of the logging-elasticsearch5 container. ElasticSearch's security team has stated that this vulnerability does not poses a substantial practical threat to ElasticSearch 6 [1]. We agree that this issue would be difficult to exploit these vulnerabilities on OpenShift Container Platform, so we're reducing the impact of this issue to moderate and may fix it in the future release. Red Hat Satellite ships vulnerable netty version embedded in Candlepin, however, is not directly vulnerable since HTTP requests are handled by Tomcat and not netty. [1] https://github.com/elastic/elasticsearch/issues/49396

Меры по смягчению последствий

  • Use HTTP/2 instead (clear boundaries between requests)
  • Disable reuse of backend connections eg. http-reuse never in HAProxy or whatever equivalent LB settings

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Clients 2nettyNot affected
Red Hat JBoss Fuse 6nettyOut of support scope
Red Hat OpenShift Container Platform 3.11openshift3/ose-logging-elasticsearch5Will not fix
Red Hat OpenShift Container Platform 4openshift4/ose-logging-elasticsearch5Will not fix
Red Hat Satellite 6candlepinNot affected
EAP-CD 19 Tech PreviewnettyFixedRHSA-2020:233328.05.2020
Red Hat AMQnettyFixedRHSA-2020:092223.03.2020
Red Hat AMQ 7.4.3nettyFixedRHSA-2020:144514.04.2020
Red Hat Data Grid 7.3.6nettyFixedRHSA-2020:232126.05.2020
Red Hat Decision Manager 7nettyFixedRHSA-2020:319629.07.2020

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-444
https://bugzilla.redhat.com/show_bug.cgi?id=1758619netty: HTTP request smuggling by mishandled whitespace before the colon in HTTP headers

EPSS

Процентиль: 86%
0.03007
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 6 лет назад

Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling.

CVSS3: 7.5
nvd
больше 6 лет назад

Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling.

CVSS3: 7.5
debian
больше 6 лет назад

Netty before 4.1.42.Final mishandles whitespace before the colon in HT ...

CVSS3: 7.5
github
больше 6 лет назад

HTTP Request Smuggling in Netty

CVSS3: 7.5
fstec
больше 6 лет назад

Уязвимость NIO-инфраструктуры клиент/сервер для Java Netty, связанная с непоследовательной интерпретацией http-запросов, позволяющая нарушителю оказать воздействие на целостность данных

EPSS

Процентиль: 86%
0.03007
Низкий

7.5 High

CVSS3