NA

CVE-2024-1135

Published: 16/04/2024 Updated: 16/04/2024

Vulnerability Summary

Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability allows for a range of attacks including cache poisoning, session manipulation, and data exposure.

Vulnerability Trend

Vendor Advisories

Debian Bug report logs - #1069126 gunicorn: CVE-2024-1135 Package: src:gunicorn; Maintainer for src:gunicorn is Debian Python Team <team+python@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 16 Apr 2024 19:24:02 UTC Severity: important Tags: security, upstream Found in version ...