Inconsistent interpretation of HTTP requests in aiohttp - CVE-2024-52304

 

Inconsistent interpretation of HTTP requests in aiohttp - CVE-2024-52304

Published: November 19, 2024 / Updated: January 29, 2025


Vulnerability identifier: #VU100600
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-52304
CWE-ID: CWE-444
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform HTTP request smuggling attacks.

The vulnerability exists due to improper validation of HTTP requests. A remote attacker can send a specially crafted HTTP request to the server and smuggle arbitrary HTTP headers.

Successful exploitation of vulnerability may allow an attacker to poison HTTP cache and perform phishing attacks.


Affected software

aiohttp
Debian Linux
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Manager Server
Fedora
Public Cloud Module
Python 3 Module
openSUSE Leap
openEuler
IBM Cloud Pak for Security
IBM Process Mining
Ansible Automation Platform
QRadar Suite
Guardium Data Security Center (GDSC)
watsonx Code Assistant for Ansible
watsonx Assistant Cartridge
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
python3.11-galaxy-importer (Red Hat package)
receptor (Red Hat package)
python3.11-yarl (Red Hat package)
python3.11-aiohappyeyeballs (Red Hat package)
ansible-automation-platform-installer (Red Hat package)
python3.11-django-ansible-base (Red Hat package)
automation-gateway (Red Hat package)
ansible-core (Red Hat package)
python3.11-aiodns (Red Hat package)
python-aiohttp-debugsource
python3-aiohttp
python-aiohttp-doc
python3-aiohttp-debuginfo
python-aiohttp
python-aiohttp-debuginfo
python-aiohttp-help
python-aiohttp (Debian package)
python311-aiohttp-debuginfo
python311-aiohttp
python3.11-aiohttp (Red Hat package)
python3.11-pulpcore (Red Hat package)
automation-controller (Red Hat package)

How to mitigate CVE-2024-52304

Install updates from vendor's website.

aiohttp - update to 3.10.11
IBM Cloud Pak for Security - update to 1.11.3.0
QRadar Suite - update to 1.11.3.0
IBM Process Mining - update to 2.0
Guardium Data Security Center (GDSC) - update to 3.8.5
watsonx Code Assistant for Ansible - update to 5.1.1
python3.11-galaxy-importer (Red Hat package) - addressed in versions 0.4.27-1.el8ap, 0.4.27-1.el9ap
receptor (Red Hat package) - addressed in versions 1.5.1-2.el8ap, 1.5.1-2.el9ap
python3.11-yarl (Red Hat package) - addressed in versions 1.13.1-1.el8ap, 1.13.1-1.el9ap
Ansible Automation Platform - addressed in versions 2.4, 2.5
python3.11-aiohappyeyeballs (Red Hat package) - addressed in versions 2.4.4-1.el8ap, 2.4.4-1.el9ap
ansible-automation-platform-installer (Red Hat package) - addressed in versions 2.5-6.el8ap, 2.5-6.el9ap, 2.5-7.el8ap, 2.5-7.el9ap
python3.11-django-ansible-base (Red Hat package) - addressed in versions 2.5.20250115-1.el8ap, 2.5.20250115-1.el9ap
automation-gateway (Red Hat package) - addressed in versions 2.5.20250115-1.el8ap, 2.5.20250115-1.el9ap
ansible-core (Red Hat package) - addressed in versions 2.16.14-2.el8ap, 2.16.14-2.el9ap
python3.11-aiodns (Red Hat package) - addressed in versions 3.2.0-1.el8ap, 3.2.0-1.el9ap
python-aiohttp-debugsource - addressed in versions 3.6.0-150100.3.18.1, 3.9.3-150400.10.27.1
python3-aiohttp - update to 3.6.0-150100.3.18.1
python-aiohttp-doc - update to 3.6.0-150100.3.18.1
python3-aiohttp-debuginfo - update to 3.6.0-150100.3.18.1
python3-aiohttp - addressed in versions 3.7.4-4, 3.7.4-5, 3.9.3-6
python-aiohttp - addressed in versions 3.7.4-4, 3.7.4-5, 3.9.3-6
python-aiohttp-debuginfo - addressed in versions 3.7.4-4, 3.7.4-5, 3.9.3-6
python-aiohttp-help - addressed in versions 3.7.4-4, 3.7.4-5, 3.9.3-6
python-aiohttp-debugsource - addressed in versions 3.7.4-4, 3.7.4-5, 3.9.3-6
python-aiohttp - addressed in versions 3.7.4-7.el8, 3.9.5-2.el9, 3.9.5-2.fc39, 3.9.5-2.fc40, 3.10.5-3.fc41
python-aiohttp (Debian package) - update to 3.8.4-1+deb12u1
python311-aiohttp-debuginfo - update to 3.9.3-150400.10.27.1
python311-aiohttp - update to 3.9.3-150400.10.27.1
python3.11-aiohttp (Red Hat package) - addressed in versions 3.10.11-1.el8ap, 3.10.11-1.el9ap
python3.11-pulpcore (Red Hat package) - addressed in versions 3.49.29-1.el8ap, 3.49.29-1.el9ap
automation-controller (Red Hat package) - addressed in versions 4.6.3-1.el8ap, 4.6.3-1.el9ap, 4.6.6-1.el8ap, 4.6.6-1.el9ap
watsonx Assistant Cartridge - update to 5.1.3
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.1.3

External References

Related Security Bulletins