CVE-2021-21409

Inconsistent Interpretation of HTTP Requests (HTTP Request Smuggling) in maven/org.apache.zookeeper/zookeeper

Identifier

CVE-2021-21409

Package Slug

maven/org.apache.zookeeper/zookeeper

Vulnerability

Inconsistent Interpretation of HTTP Requests (HTTP Request Smuggling)

Description

Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2), which is used by zookeeper, there is a vulnerability that enables request smuggling. The content-length header is not correctly validated if the request only uses a single Http2HeaderFrame with the endStream set to to true. This could lead to request smuggling if the request is proxied to a remote peer and translated to HTTP/1.1. This is a followup of GHSA-wm47-8v5p-wjpj/CVE-2021-21295 which did miss to fix this one case.

Affected Versions

All versions before 3.6.3, all versions starting from 3.7.0 before 3.7.1

Solution

Upgrade to version 3.6.3, 3.7.1 or above.

Last Modified

2021-04-23

source