Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2025:1002-1

Опубликовано: 25 мар. 2025
Источник: suse-cvrf

Описание

Security update for python-gunicorn

This update for python-gunicorn fixes the following issues:

  • CVE-2024-6827: Fixed improper validation of the 'Transfer-Encoding' header value can allow for HTTP request smuggling attacks (bsc#1239830)

Список пакетов

SUSE Linux Enterprise Module for Public Cloud 15 SP3
python3-gunicorn-19.7.1-150000.3.10.1
SUSE Linux Enterprise Module for Public Cloud 15 SP4
python3-gunicorn-19.7.1-150000.3.10.1
SUSE Linux Enterprise Module for Public Cloud 15 SP5
python3-gunicorn-19.7.1-150000.3.10.1
SUSE Linux Enterprise Module for Public Cloud 15 SP6
python3-gunicorn-19.7.1-150000.3.10.1

Описание

Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse.


Затронутые продукты
SUSE Linux Enterprise Module for Public Cloud 15 SP3:python3-gunicorn-19.7.1-150000.3.10.1
SUSE Linux Enterprise Module for Public Cloud 15 SP4:python3-gunicorn-19.7.1-150000.3.10.1
SUSE Linux Enterprise Module for Public Cloud 15 SP5:python3-gunicorn-19.7.1-150000.3.10.1
SUSE Linux Enterprise Module for Public Cloud 15 SP6:python3-gunicorn-19.7.1-150000.3.10.1

Ссылки