Описание
Security update for python-gunicorn
This update for python-gunicorn fixes the following issues:
- CVE-2024-6827: Fixed improper validation of the 'Transfer-Encoding' header value can allow for HTTP request smuggling attacks (bsc#1239830)
Список пакетов
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
python311-gunicorn-20.1.0-150400.12.9.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
python311-gunicorn-20.1.0-150400.12.9.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS
python311-gunicorn-20.1.0-150400.12.9.1
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS
python311-gunicorn-20.1.0-150400.12.9.1
SUSE Linux Enterprise Module for Python 3 15 SP6
python311-gunicorn-20.1.0-150400.12.9.1
SUSE Linux Enterprise Server 15 SP4-LTSS
python311-gunicorn-20.1.0-150400.12.9.1
SUSE Linux Enterprise Server 15 SP5-LTSS
python311-gunicorn-20.1.0-150400.12.9.1
SUSE Linux Enterprise Server for SAP Applications 15 SP4
python311-gunicorn-20.1.0-150400.12.9.1
SUSE Linux Enterprise Server for SAP Applications 15 SP5
python311-gunicorn-20.1.0-150400.12.9.1
openSUSE Leap 15.6
python311-gunicorn-20.1.0-150400.12.9.1
Ссылки
- Link for SUSE-SU-2025:1008-1
- E-Mail link for SUSE-SU-2025:1008-1
- SUSE Security Ratings
- SUSE Bug 1239830
- SUSE CVE CVE-2024-6827 page
Описание
Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse.
Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:python311-gunicorn-20.1.0-150400.12.9.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:python311-gunicorn-20.1.0-150400.12.9.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:python311-gunicorn-20.1.0-150400.12.9.1
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS:python311-gunicorn-20.1.0-150400.12.9.1
Ссылки
- CVE-2024-6827
- SUSE Bug 1239830