The vendor explicitly identifies these products as affected by this CVE.
- exploit-intelligence/agent-client-rhel9 as a component of Exploit Intelligence
- openshift-serverless-1/kn-ekb-dispatcher-rhel9 as a component of OpenShift Serverless
- openshift-serverless-1/kn-ekb-receiver-rhel9 as a component of OpenShift Serverless
- openshift-serverless-1/kn-eventing-integrations-aws-ddb-streams-source-rhel9 as a component of OpenShift Serverless
- openshift-serverless-1/kn-eventing-integrations-aws-s3-sink-rhel9 as a component of OpenShift Serverless
- openshift-serverless-1/kn-eventing-integrations-aws-s3-source-rhel9 as a component of OpenShift Serverless
- openshift-serverless-1/kn-eventing-integrations-aws-sns-sink-rhel9 as a component of OpenShift Serverless
- openshift-serverless-1/kn-eventing-integrations-aws-sqs-sink-rhel9 as a component of OpenShift Serverless
- openshift-serverless-1/kn-eventing-integrations-aws-sqs-source-rhel9 as a component of OpenShift Serverless
- openshift-serverless-1/kn-eventing-integrations-log-sink-rhel9 as a component of OpenShift Serverless
- openshift-serverless-1/kn-eventing-integrations-timer-source-rhel9 as a component of OpenShift Serverless
- netty-codec-socks as a component of Red Hat AMQ Broker 7
- Summary
- A flaw was found in the Netty SOCKS client encoders. This vulnerability allows a remote attacker to inject null bytes or Carriage Return Line Feed (CRLF) characters into domain address and authentication fields due to insufficient validation. By manipulating these fields, an attacker can truncate or alter values, potentially leading to domain spoofing, SOCKS4 user ID truncation, authentication data injection, and protocol confusion.
- Remediation
- Applications utilizing Netty's SOCKS client encoders should implement robust input validation and sanitization for all domain address and authentication credential fields. If SOCKS proxy client functionality is not required by the application, it should be disabled to remove the attack surface.
