Описание
A flaw was found in Netty's HTTP/1.1 decoder. This vulnerability allows a remote attacker to bypass Transfer-Encoding header validation by splitting the Transfer-Encoding field across multiple headers, with the last field containing a non-final transfer coding like gzip or deflate. This bypass can lead to HTTP request smuggling, enabling attackers to bypass security controls, desynchronize request processing, or cause requests to be processed in an unintended context.
Отчет
This flaw in Netty's HTTP/1.1 decoder allows for HTTP request smuggling by incorrectly processing split Transfer-Encoding headers. When Netty is deployed with an intermediary that interprets these headers differently, an attacker could bypass front-end security controls or desynchronize request processing.
Меры по смягчению последствий
See https://github.com/netty/netty/security/advisories/GHSA-3jrc-fchc-59pw for fixed versions and remediation guidance.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat AMQ Broker 7 | netty-codec-http | Fix deferred | ||
| Red Hat AMQ Clients | netty-codec-http | Fix deferred | ||
| Red Hat build of Apache Camel 4 for Quarkus 3 | netty-codec-http | Fix deferred | ||
| Red Hat build of Apache Camel for Spring Boot 4 | netty-codec-http | Fix deferred | ||
| Red Hat build of Apicurio Registry 3 | netty-codec-http | Out of support scope | ||
| Red Hat build of Debezium 3 | netty-codec-http | Fix deferred | ||
| Red Hat Build of Keycloak | netty-codec-http | Out of support scope | ||
| Red Hat build of Quarkus | netty-codec-http | Fix deferred | ||
| Red Hat Data Grid 8 | netty-codec-http | Out of support scope | ||
| Red Hat Fuse 7 | netty-codec-http | Out of support scope |
Показывать по
Дополнительная информация
Статус:
6.5 Medium
CVSS3
Связанные уязвимости
A flaw was found in Netty's HTTP/1.1 decoder. This vulnerability allows a remote attacker to bypass `Transfer-Encoding` header validation by splitting the `Transfer-Encoding` field across multiple headers, with the last field containing a non-final transfer coding like `gzip` or `deflate`. This bypass can lead to HTTP request smuggling, enabling attackers to bypass security controls, desynchronize request processing, or cause requests to be processed in an unintended context.
A flaw was found in Netty's HTTP/1.1 decoder. This vulnerability allow ...
Netty split Transfer-Encoding fields bypass final-chunked validation and enable request smuggling
6.5 Medium
CVSS3