Io.netty/netty-codec-http: netty rtspdecoder method-token smuggling via trailing control byte
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.5epss 0.4%
exploitation probability
0.4%top 70% of all CVEs
observed exploitation
nono source reports it
A flaw was found in Netty RtspDecoder. The `RtspMethods.valueOf()` function incorrectly strips trailing control bytes from method tokens in Real-Time Streaming Protocol (RTSP) requests. A remote attacker can exploit this by sending a specially crafted RTSP request, leading to method-token smuggling. This vulnerability allows an attacker to bypass method-based access controls and can also be used to launder malicious requests through Netty-based RTSP proxies, making them appear legitimate to backend systems.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected products
Red Hat · Red Hat AMQ Broker 7Red Hat · Red Hat AMQ ClientsRed Hat · Red Hat build of Apache Camel 4 for Quarkus 3Red Hat · Red Hat build of Apache Camel for Spring Boot 4Red Hat · Red Hat build of Apicurio Registry 3Red Hat · Red Hat build of Debezium 3Red Hat · Red Hat Build of KeycloakRed Hat · Red Hat Data Grid 8Red Hat · Red Hat Fuse 7Red Hat · Red Hat JBoss Enterprise Application Platform 7Red Hat · Red Hat JBoss Enterprise Application Platform 8Red Hat · Red Hat Single Sign-On 7