Inconsistent interpretation of HTTP requests in aiohttp - CVE-2024-52304
Published: November 19, 2024 / Updated: January 29, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform HTTP request smuggling attacks.
The vulnerability exists due to improper validation of HTTP requests. A remote attacker can send a specially crafted HTTP request to the server and smuggle arbitrary HTTP headers.
Successful exploitation of vulnerability may allow an attacker to poison HTTP cache and perform phishing attacks.
Affected software
Debian Linux
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Manager Server
Fedora
Public Cloud Module
Python 3 Module
openSUSE Leap
openEuler
IBM Cloud Pak for Security
IBM Process Mining
Ansible Automation Platform
QRadar Suite
Guardium Data Security Center (GDSC)
watsonx Code Assistant for Ansible
watsonx Assistant Cartridge
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
python3.11-galaxy-importer (Red Hat package)
receptor (Red Hat package)
python3.11-yarl (Red Hat package)
python3.11-aiohappyeyeballs (Red Hat package)
ansible-automation-platform-installer (Red Hat package)
python3.11-django-ansible-base (Red Hat package)
automation-gateway (Red Hat package)
ansible-core (Red Hat package)
python3.11-aiodns (Red Hat package)
python-aiohttp-debugsource
python3-aiohttp
python-aiohttp-doc
python3-aiohttp-debuginfo
python-aiohttp
python-aiohttp-debuginfo
python-aiohttp-help
python-aiohttp (Debian package)
python311-aiohttp-debuginfo
python311-aiohttp
python3.11-aiohttp (Red Hat package)
python3.11-pulpcore (Red Hat package)
automation-controller (Red Hat package)
How to mitigate CVE-2024-52304
IBM Cloud Pak for Security - update to 1.11.3.0
QRadar Suite - update to 1.11.3.0
IBM Process Mining - update to 2.0
Guardium Data Security Center (GDSC) - update to 3.8.5
watsonx Code Assistant for Ansible - update to 5.1.1
python3.11-galaxy-importer (Red Hat package) - addressed in versions 0.4.27-1.el8ap, 0.4.27-1.el9ap
receptor (Red Hat package) - addressed in versions 1.5.1-2.el8ap, 1.5.1-2.el9ap
python3.11-yarl (Red Hat package) - addressed in versions 1.13.1-1.el8ap, 1.13.1-1.el9ap
Ansible Automation Platform - addressed in versions 2.4, 2.5
python3.11-aiohappyeyeballs (Red Hat package) - addressed in versions 2.4.4-1.el8ap, 2.4.4-1.el9ap
ansible-automation-platform-installer (Red Hat package) - addressed in versions 2.5-6.el8ap, 2.5-6.el9ap, 2.5-7.el8ap, 2.5-7.el9ap
python3.11-django-ansible-base (Red Hat package) - addressed in versions 2.5.20250115-1.el8ap, 2.5.20250115-1.el9ap
automation-gateway (Red Hat package) - addressed in versions 2.5.20250115-1.el8ap, 2.5.20250115-1.el9ap
ansible-core (Red Hat package) - addressed in versions 2.16.14-2.el8ap, 2.16.14-2.el9ap
python3.11-aiodns (Red Hat package) - addressed in versions 3.2.0-1.el8ap, 3.2.0-1.el9ap
python-aiohttp-debugsource - addressed in versions 3.6.0-150100.3.18.1, 3.9.3-150400.10.27.1
python3-aiohttp - update to 3.6.0-150100.3.18.1
python-aiohttp-doc - update to 3.6.0-150100.3.18.1
python3-aiohttp-debuginfo - update to 3.6.0-150100.3.18.1
python3-aiohttp - addressed in versions 3.7.4-4, 3.7.4-5, 3.9.3-6
python-aiohttp - addressed in versions 3.7.4-4, 3.7.4-5, 3.9.3-6
python-aiohttp-debuginfo - addressed in versions 3.7.4-4, 3.7.4-5, 3.9.3-6
python-aiohttp-help - addressed in versions 3.7.4-4, 3.7.4-5, 3.9.3-6
python-aiohttp-debugsource - addressed in versions 3.7.4-4, 3.7.4-5, 3.9.3-6
python-aiohttp - addressed in versions 3.7.4-7.el8, 3.9.5-2.el9, 3.9.5-2.fc39, 3.9.5-2.fc40, 3.10.5-3.fc41
python-aiohttp (Debian package) - update to 3.8.4-1+deb12u1
python311-aiohttp-debuginfo - update to 3.9.3-150400.10.27.1
python311-aiohttp - update to 3.9.3-150400.10.27.1
python3.11-aiohttp (Red Hat package) - addressed in versions 3.10.11-1.el8ap, 3.10.11-1.el9ap
python3.11-pulpcore (Red Hat package) - addressed in versions 3.49.29-1.el8ap, 3.49.29-1.el9ap
automation-controller (Red Hat package) - addressed in versions 4.6.3-1.el8ap, 4.6.3-1.el9ap, 4.6.6-1.el8ap, 4.6.6-1.el9ap
watsonx Assistant Cartridge - update to 5.1.3
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.1.3
External References
Related Security Bulletins
- Multiple vulnerabilities in aiohttp
- Fedora 41 update for python-aiohttp
- Fedora 40 update for python-aiohttp
- Fedora 39 update for python-aiohttp
- Fedora EPEL 9 update for python-aiohttp
- Fedora EPEL 8 update for python-aiohttp
- SUSE update for python-aiohttp
- SUSE update for python-aiohttp
- Inconsistent interpretation of HTTP requests in Ansible Automation Platform 2.5 packages
- Debian update for python-aiohttp
- Multiple vulnerabilities in Ansible Automation Platform 2.5 packages
- Multiple vulnerabilities in Ansible Automation Platform 2.5 packages
- openEuler 24.03 LTS update for python-aiohttp
- openEuler 22.03 LTS SP4 update for python-aiohttp
- openEuler 20.03 LTS SP4 update for python-aiohttp
- openEuler 22.03 LTS SP3 update for python-aiohttp
- Multiple vulnerabilities in Ansible Automation Platform 2.4 packages
- IBM watsonx Code Assistant On Prem update for aiohttp
- Multiple vulnerabilities in IBM Process Mining
- IBM watsonx Assistant Cartridge and IBM watsonx Orchestrate with watsonx Assistant Cartridge update for aiohttp
- Multiple vulnerabilities in IBM Cloud Pak for Security and IBM QRadar Suite Software
- Multiple vulnerabilities in IBM Guardium Data Security Center