Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-1135

Опубликовано: 15 апр. 2024
Источник: redhat
CVSS3: 7.5

Описание

Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability allows for a range of attacks including cache poisoning, session manipulation, and data exposure.

An HTTP Request Smuggling vulnerability was found in Gunicorn. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability allows for a range of attacks, including cache poisoning, session manipulation, and data exposure.

Меры по смягчению последствий

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Discovery 1discovery-server-containerNot affected
Red Hat Enterprise Linux 7python-gunicornWill not fix
Red Hat OpenStack Platform 16.1python-gunicornOut of support scope
Red Hat OpenStack Platform 18.0python-gunicornAffected
Red Hat Quay 3quay/quay-rhel8Affected
Red Hat Storage 3graphite-webAffected
Red Hat Ansible Automation Platform 2.4 for RHEL 8python3x-gunicornFixedRHSA-2024:378110.06.2024
Red Hat Ansible Automation Platform 2.4 for RHEL 9python-gunicornFixedRHSA-2024:378110.06.2024
Red Hat OpenShift Container Platform 4.12openshift4/ose-ironic-rhel9FixedRHSA-2024:371312.06.2024
Red Hat OpenShift Container Platform 4.13openshift4/ose-ironic-rhel9FixedRHSA-2024:287523.05.2024

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-444
https://bugzilla.redhat.com/show_bug.cgi?id=2275280python-gunicorn: HTTP Request Smuggling due to improper validation of Transfer-Encoding headers

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 2 года назад

Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability allows for a range of attacks including cache poisoning, session manipulation, and data exposure.

CVSS3: 7.5
nvd
почти 2 года назад

Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability allows for a range of attacks including cache poisoning, session manipulation, and data exposure.

CVSS3: 7.5
debian
почти 2 года назад

Gunicorn fails to properly validate Transfer-Encoding headers, leading ...

suse-cvrf
больше 1 года назад

Security update for python-gunicorn

suse-cvrf
больше 1 года назад

Security update for python-gunicorn

7.5 High

CVSS3