cbcvebase.
CVE-2022-41915
published 2022-12-13

CVE-2022-41915: Netty project is an event-driven asynchronous network application framework. Starting in version 4.1.83.Final and prior to 4.1.86.Final, when calling…

PriorityP434medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
0.89%
55.5th percentile
Netty project is an event-driven asynchronous network application framework. Starting in version 4.1.83.Final and prior to 4.1.86.Final, when calling `DefaultHttpHeadesr.set` with an _iterator_ of values, header value validation was not performed, allowing malicious header values in the iterator to perform HTTP Response Splitting. This issue has been patched in version 4.1.86.Final. Integrators can work around the issue by changing the `DefaultHttpHeaders.set(CharSequence, Iterator)` call, into a `remove()` call, and call `add()` in a loop over the iterator of values.

Affected

14 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiannetty< netty 1:4.1.48-6 (bookworm)netty 1:4.1.48-6 (bookworm)
nettynetty>= 0 < 1:4.1.48-4+deb11u11:4.1.48-4+deb11u1
nettynetty>= 0 < 1:4.1.48-61:4.1.48-6
nettynetty>= 0 < 1:4.1.48-61:4.1.48-6
nettynetty>= 0 < 1:4.1.48-61:4.1.48-6
nettynetty>= 0 < 1:4.1.48-4+deb11u1build0.22.04.11:4.1.48-4+deb11u1build0.22.04.1
nettynetty>= 0 < 1:4.0.34-1ubuntu0.1~esm11:4.0.34-1ubuntu0.1~esm1
nettynetty>= 0 < 1:4.1.7-4ubuntu0.1+esm21:4.1.7-4ubuntu0.1+esm2
nettynetty>= 0 < 1:4.1.45-1ubuntu0.1~esm11:4.1.45-1ubuntu0.1~esm1
nettynetty>= 4.1.83 < 4.1.864.1.86
nettynetty>= 4.1.83.Final < 4.1.83.Final*4.1.83.Final*
nettynetty>= 4.1.86.Final < 4.1.86.Final4.1.86.Final

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian6.5MEDIUM
vendor_oracle6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.