CVE-2021-21409 (CNNVD-202103-1685)
中文标题:
Netty 环境问题漏洞
英文标题:
Possible request smuggling in HTTP/2 due missing validation of content-length
漏洞描述
中文描述:
Netty是Netty社区的一款非阻塞I/O客户端-服务器框架,它主要用于开发Java网络应用程序,如协议服务器和客户端等。 Netty 存在环境问题漏洞,该漏洞导致请求走私。
英文描述:
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.61.Final there is a vulnerability that enables request smuggling. The content-length header is not correctly validated if the request only uses a single Http2HeaderFrame with the endStream set to to true. This could lead to request smuggling if the request is proxied to a remote peer and translated to HTTP/1.1. This is a followup of GHSA-wm47-8v5p-wjpj/CVE-2021-21295 which did miss to fix this one case. This was fixed as part of 4.1.61.Final.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| netty | netty | < 4.1.61.Final | - | - |
cpe:2.3:a:netty:netty:<_4.1.61.final:*:*:*:*:*:*:*
|
| netty | netty | * | - | - |
cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:*
|
| debian | debian_linux | 10.0 | - | - |
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
|
| netapp | oncommand_api_services | - | - | - |
cpe:2.3:a:netapp:oncommand_api_services:-:*:*:*:*:*:*:*
|
| netapp | oncommand_workflow_automation | - | - | - |
cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:*
|
| oracle | banking_corporate_lending_process_management | 14.2.0 | - | - |
cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.2.0:*:*:*:*:*:*:*
|
| oracle | banking_corporate_lending_process_management | 14.3.0 | - | - |
cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.3.0:*:*:*:*:*:*:*
|
| oracle | banking_corporate_lending_process_management | 14.5.0 | - | - |
cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.5.0:*:*:*:*:*:*:*
|
| oracle | banking_credit_facilities_process_management | 14.2.0 | - | - |
cpe:2.3:a:oracle:banking_credit_facilities_process_management:14.2.0:*:*:*:*:*:*:*
|
| oracle | banking_credit_facilities_process_management | 14.3.0 | - | - |
cpe:2.3:a:oracle:banking_credit_facilities_process_management:14.3.0:*:*:*:*:*:*:*
|
| oracle | banking_credit_facilities_process_management | 14.5.0 | - | - |
cpe:2.3:a:oracle:banking_credit_facilities_process_management:14.5.0:*:*:*:*:*:*:*
|
| oracle | banking_trade_finance_process_management | 14.2.0 | - | - |
cpe:2.3:a:oracle:banking_trade_finance_process_management:14.2.0:*:*:*:*:*:*:*
|
| oracle | banking_trade_finance_process_management | 14.3.0 | - | - |
cpe:2.3:a:oracle:banking_trade_finance_process_management:14.3.0:*:*:*:*:*:*:*
|
| oracle | banking_trade_finance_process_management | 14.5.0 | - | - |
cpe:2.3:a:oracle:banking_trade_finance_process_management:14.5.0:*:*:*:*:*:*:*
|
| oracle | coherence | 12.2.1.4.0 | - | - |
cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
|
| oracle | coherence | 14.1.1.0.0 | - | - |
cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
|
| oracle | communications_brm_-_elastic_charging_engine | 12.0.0.3 | - | - |
cpe:2.3:a:oracle:communications_brm_-_elastic_charging_engine:12.0.0.3:*:*:*:*:*:*:*
|
| oracle | communications_cloud_native_core_console | 1.7.0 | - | - |
cpe:2.3:a:oracle:communications_cloud_native_core_console:1.7.0:*:*:*:*:*:*:*
|
| oracle | communications_cloud_native_core_policy | 1.14.0 | - | - |
cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.14.0:*:*:*:*:*:*:*
|
| oracle | communications_design_studio | 7.4.2.0.0 | - | - |
cpe:2.3:a:oracle:communications_design_studio:7.4.2.0.0:*:*:*:*:*:*:*
|
| oracle | communications_messaging_server | 8.1 | - | - |
cpe:2.3:a:oracle:communications_messaging_server:8.1:*:*:*:*:*:*:*
|
| oracle | helidon | 1.4.10 | - | - |
cpe:2.3:a:oracle:helidon:1.4.10:*:*:*:*:*:*:*
|
| oracle | helidon | 2.4.0 | - | - |
cpe:2.3:a:oracle:helidon:2.4.0:*:*:*:*:*:*:*
|
| oracle | jd_edwards_enterpriseone_tools | * | - | - |
cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:*:*:*:*:*:*:*:*
|
| oracle | nosql_database | * | - | - |
cpe:2.3:a:oracle:nosql_database:*:*:*:*:*:*:*:*
|
| oracle | primavera_gateway | * | - | - |
cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:*
|
| quarkus | quarkus | * | - | - |
cpe:2.3:a:quarkus:quarkus:*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
CVSS评分详情
3.1 (cna)
MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2021-21409 |
2025-11-11 15:20:48 | 2025-11-11 07:36:37 |
| NVD | nvd_CVE-2021-21409 |
2025-11-11 14:57:35 | 2025-11-11 07:44:58 |
| CNNVD | cnnvd_CNNVD-202103-1685 |
2025-11-11 15:10:36 | 2025-11-11 07:56:39 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 环境问题
- cnnvd_id: 未提取 -> CNNVD-202103-1685
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 1 -> 27
- data_sources: ['cve'] -> ['cve', 'nvd']