Логотип exploitDog
bind:"BDU:2022-00303" OR bind:"CVE-2021-21295"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2022-00303" OR bind:"CVE-2021-21295"

Количество 9

Количество 9

fstec логотип

BDU:2022-00303

больше 4 лет назад

Уязвимость класса Http2MultiplexHandler сетевого программного средства Netty, связанная с недостатком в интерпретации HTTP-запросов, позволяющая нарушителю оказать воздействие на целостность данных

CVSS3: 5.9
EPSS: Низкий
redos логотип

ROS-20220125-11

больше 3 лет назад

Уязвимость сетевого программного средства Netty

EPSS: Низкий
ubuntu логотип

CVE-2021-21295

больше 4 лет назад

Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.60.Final there is a vulnerability that enables request smuggling. If a Content-Length header is present in the original HTTP/2 request, the field is not validated by `Http2MultiplexHandler` as it is propagated up. This is fine as long as the request is not proxied through as HTTP/1.1. If the request comes in as an HTTP/2 stream, gets converted into the HTTP/1.1 domain objects (`HttpRequest`, `HttpContent`, etc.) via `Http2StreamFrameToHttpObjectCodec `and then sent up to the child channel's pipeline and proxied through a remote peer as HTTP/1.1 this may result in request smuggling. In a proxy case, users may assume the content-length is validated somehow, which is not the case. If the request is forwarded to a backend channel that is a HTTP/1.1 connection, the Conte...

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2021-21295

больше 4 лет назад

Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.60.Final there is a vulnerability that enables request smuggling. If a Content-Length header is present in the original HTTP/2 request, the field is not validated by `Http2MultiplexHandler` as it is propagated up. This is fine as long as the request is not proxied through as HTTP/1.1. If the request comes in as an HTTP/2 stream, gets converted into the HTTP/1.1 domain objects (`HttpRequest`, `HttpContent`, etc.) via `Http2StreamFrameToHttpObjectCodec `and then sent up to the child channel's pipeline and proxied through a remote peer as HTTP/1.1 this may result in request smuggling. In a proxy case, users may assume the content-length is validated somehow, which is not the case. If the request is forwarded to a backend channel that is a HTTP/1.1 connection, the Conte...

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2021-21295

больше 4 лет назад

Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.60.Final there is a vulnerability that enables request smuggling. If a Content-Length header is present in the original HTTP/2 request, the field is not validated by `Http2MultiplexHandler` as it is propagated up. This is fine as long as the request is not proxied through as HTTP/1.1. If the request comes in as an HTTP/2 stream, gets converted into the HTTP/1.1 domain objects (`HttpRequest`, `HttpContent`, etc.) via `Http2StreamFrameToHttpObjectCodec `and then sent up to the child channel's pipeline and proxied through a remote peer as HTTP/1.1 this may result in request smuggling. In a proxy case, users may assume the content-length is validated somehow, which is not the case. If the request is forwarded to a backend channel that is a HTTP/1.1 connection, the Content-

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2021-21295

больше 4 лет назад

Netty is an open-source, asynchronous event-driven network application ...

CVSS3: 5.9
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:0448-1

больше 4 лет назад

Security update for netty

EPSS: Низкий
github логотип

GHSA-wm47-8v5p-wjpj

больше 4 лет назад

Possible request smuggling in HTTP/2 due missing validation

CVSS3: 5.9
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:1271-1

около 3 лет назад

Security update for netty

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2022-00303

Уязвимость класса Http2MultiplexHandler сетевого программного средства Netty, связанная с недостатком в интерпретации HTTP-запросов, позволяющая нарушителю оказать воздействие на целостность данных

CVSS3: 5.9
1%
Низкий
больше 4 лет назад
redos логотип
ROS-20220125-11

Уязвимость сетевого программного средства Netty

больше 3 лет назад
ubuntu логотип
CVE-2021-21295

Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.60.Final there is a vulnerability that enables request smuggling. If a Content-Length header is present in the original HTTP/2 request, the field is not validated by `Http2MultiplexHandler` as it is propagated up. This is fine as long as the request is not proxied through as HTTP/1.1. If the request comes in as an HTTP/2 stream, gets converted into the HTTP/1.1 domain objects (`HttpRequest`, `HttpContent`, etc.) via `Http2StreamFrameToHttpObjectCodec `and then sent up to the child channel's pipeline and proxied through a remote peer as HTTP/1.1 this may result in request smuggling. In a proxy case, users may assume the content-length is validated somehow, which is not the case. If the request is forwarded to a backend channel that is a HTTP/1.1 connection, the Conte...

CVSS3: 5.9
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2021-21295

Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.60.Final there is a vulnerability that enables request smuggling. If a Content-Length header is present in the original HTTP/2 request, the field is not validated by `Http2MultiplexHandler` as it is propagated up. This is fine as long as the request is not proxied through as HTTP/1.1. If the request comes in as an HTTP/2 stream, gets converted into the HTTP/1.1 domain objects (`HttpRequest`, `HttpContent`, etc.) via `Http2StreamFrameToHttpObjectCodec `and then sent up to the child channel's pipeline and proxied through a remote peer as HTTP/1.1 this may result in request smuggling. In a proxy case, users may assume the content-length is validated somehow, which is not the case. If the request is forwarded to a backend channel that is a HTTP/1.1 connection, the Conte...

CVSS3: 5.9
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-21295

Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.60.Final there is a vulnerability that enables request smuggling. If a Content-Length header is present in the original HTTP/2 request, the field is not validated by `Http2MultiplexHandler` as it is propagated up. This is fine as long as the request is not proxied through as HTTP/1.1. If the request comes in as an HTTP/2 stream, gets converted into the HTTP/1.1 domain objects (`HttpRequest`, `HttpContent`, etc.) via `Http2StreamFrameToHttpObjectCodec `and then sent up to the child channel's pipeline and proxied through a remote peer as HTTP/1.1 this may result in request smuggling. In a proxy case, users may assume the content-length is validated somehow, which is not the case. If the request is forwarded to a backend channel that is a HTTP/1.1 connection, the Content-

CVSS3: 5.9
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-21295

Netty is an open-source, asynchronous event-driven network application ...

CVSS3: 5.9
1%
Низкий
больше 4 лет назад
suse-cvrf логотип
openSUSE-SU-2021:0448-1

Security update for netty

1%
Низкий
больше 4 лет назад
github логотип
GHSA-wm47-8v5p-wjpj

Possible request smuggling in HTTP/2 due missing validation

CVSS3: 5.9
1%
Низкий
больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2022:1271-1

Security update for netty

около 3 лет назад

Уязвимостей на страницу