Inconsistent interpretation of HTTP requests in WEBrick - CVE-2024-47220
Published: October 8, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform HTTP request smuggling attacks.
The vulnerability exists due to improper validation of HTTP requests. A remote attacker can send a specially crafted HTTP request containing both a Content-Length header and a Transfer-Encoding header to the server and smuggle arbitrary HTTP headers.
Successful exploitation of vulnerability may allow an attacker to poison HTTP cache and perform phishing attacks.
Affected software
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
BIG-IP Next CNF
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Enterprise Storage
SUSE Linux Enterprise Server 12 SP5 LTSS
SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security
Basesystem Module
openSUSE Leap
Ubuntu
openEuler
rubygem-net-telnet
rubygem-xmlrpc
rubygem-io-console
rubygem-power_assert
rubygem-did_you_mean
rubygem-bigdecimal
rubygem-webrick-help
rubygem-webrick
ruby-webrick (Ubuntu package)
rubygem-json
rubygem-openssl
libruby2_1-2_1
libruby2_1-2_1-debuginfo
ruby2.1-debuginfo
ruby2.1-stdlib-debuginfo
ruby2.1-stdlib
ruby2.1-debugsource
ruby2.1
ruby2.3 (Ubuntu package)
ruby-help
ruby
ruby-irb
ruby-debuginfo
ruby-debugsource
ruby-devel
ruby2.5-debuginfo
ruby2.5
libruby2_5-2_5-debuginfo
ruby2.5-stdlib
ruby2.5-debugsource
ruby2.5-doc
ruby2.5-doc-ri
ruby2.5-stdlib-debuginfo
libruby2_5-2_5
ruby2.5-devel
ruby2.5-devel-extra
rubygems
rubygems-devel
rubygem-psych
rubygem-test-unit
rubygem-minitest
rubygem-rdoc
rubygem-rake
APEX Cloud Platform for Microsoft Azure
Storage Resource Manager
APEX Cloud Platform for Red Hat OpenShift
OpenShift Logging
Dell Secure Connect Gateway
PowerProtect Data Manager
Dell EMC Storage Monitoring and Reporting (SMR)
How to mitigate CVE-2024-47220
BIG-IP Next CNF - update to 1.4.0
rubygem-net-telnet - update to 0.1.1-130
rubygem-xmlrpc - update to 0.3.0-130
rubygem-io-console - update to 0.4.6-130
rubygem-power_assert - update to 1.1.1-130
rubygem-did_you_mean - update to 1.2.0-130
rubygem-bigdecimal - update to 1.3.4-130
APEX Cloud Platform for Microsoft Azure - addressed in versions 01.04.01.00, 01.05.01.00
rubygem-webrick-help - update to 1.7.0-2
rubygem-webrick - update to 1.7.0-2
ruby-webrick (Ubuntu package) - addressed in versions 1.7.0-3ubuntu0.1, 1.8.1-1ubuntu0.1
rubygem-json - update to 2.1.0-130
rubygem-openssl - update to 2.1.2-130
libruby2_1-2_1 - update to 2.1.9-19.9.1
libruby2_1-2_1-debuginfo - update to 2.1.9-19.9.1
ruby2.1-debuginfo - update to 2.1.9-19.9.1
ruby2.1-stdlib-debuginfo - update to 2.1.9-19.9.1
ruby2.1-stdlib - update to 2.1.9-19.9.1
ruby2.1-debugsource - update to 2.1.9-19.9.1
ruby2.1 - update to 2.1.9-19.9.1
ruby2.3 (Ubuntu package) - addressed in versions 2.3.1-2~ubuntu16.04.16+esm11, 2.5.1-1ubuntu1.16+esm6, 2.7.0-5ubuntu1.18+esm3
ruby-help - update to 2.5.8-130
ruby - update to 2.5.8-130
ruby-irb - update to 2.5.8-130
ruby-debuginfo - update to 2.5.8-130
ruby-debugsource - update to 2.5.8-130
ruby-devel - update to 2.5.8-130
ruby2.5-debuginfo - addressed in versions 2.5.9-150000.4.36.1, 2.5.9-150000.4.41.1, 2.5.9-150700.24.3.1
ruby2.5 - addressed in versions 2.5.9-150000.4.36.1, 2.5.9-150000.4.41.1, 2.5.9-150700.24.3.1
libruby2_5-2_5-debuginfo - addressed in versions 2.5.9-150000.4.36.1, 2.5.9-150000.4.41.1, 2.5.9-150700.24.3.1
ruby2.5-stdlib - addressed in versions 2.5.9-150000.4.36.1, 2.5.9-150000.4.41.1, 2.5.9-150700.24.3.1
ruby2.5-debugsource - addressed in versions 2.5.9-150000.4.36.1, 2.5.9-150000.4.41.1, 2.5.9-150700.24.3.1
ruby2.5-doc - addressed in versions 2.5.9-150000.4.36.1, 2.5.9-150000.4.41.1
ruby2.5-doc-ri - addressed in versions 2.5.9-150000.4.36.1, 2.5.9-150000.4.41.1
ruby2.5-stdlib-debuginfo - addressed in versions 2.5.9-150000.4.36.1, 2.5.9-150000.4.41.1, 2.5.9-150700.24.3.1
libruby2_5-2_5 - addressed in versions 2.5.9-150000.4.36.1, 2.5.9-150000.4.41.1, 2.5.9-150700.24.3.1
ruby2.5-devel - addressed in versions 2.5.9-150000.4.36.1, 2.5.9-150000.4.41.1, 2.5.9-150700.24.3.1
ruby2.5-devel-extra - addressed in versions 2.5.9-150000.4.36.1, 2.5.9-150000.4.41.1, 2.5.9-150700.24.3.1
rubygems - update to 2.7.6-130
rubygems-devel - update to 2.7.6-130
rubygem-psych - update to 3.0.2-130
APEX Cloud Platform for Red Hat OpenShift - update to 03.02.04.00
rubygem-test-unit - update to 3.2.7-130
Dell EMC Storage Monitoring and Reporting (SMR) - addressed in versions 5.0.2.2, 5.1.0.0
Storage Resource Manager - addressed in versions 5.0.2.2, 5.1.0.0
OpenShift Logging - update to 5.9.11
rubygem-minitest - update to 5.10.3-130
Dell Secure Connect Gateway - update to 5.28.00.14
rubygem-rdoc - update to 6.0.1.1-130
rubygem-rake - update to 12.3.0-130
PowerProtect Data Manager - update to 19.19.0-15
External References
Related Security Bulletins
- HTTP request smuggling in WEBrick toolkit
- Ubuntu update for ruby-webrick
- Ubuntu update for ruby-webrick
- openEuler 20.03 LTS SP4 update for ruby
- openEuler update for rubygem-webrick
- SUSE update for ruby2.1
- Multiple vulnerabilities in OpenShift Logging 5.9
- SUSE update for ruby2.5
- SUSE update for ruby2.5
- Dell APEX Cloud Platform for Red Hat OpenShift update for third-party components
- Multiple vulnerabilities in Dell PowerProtect Data Manager
- Dell APEX Cloud Platform for Microsoft Azure update for third-party components
- Multiple vulnerabilities in Dell Secure Connect Gateway
- Multiple vulnerabilities in Dell Storage Resource Manager (SRM) and Dell Storage Monitoring and Reporting (SMR)
- Multiple vulnerabilities in Dell Storage Resource Manager (SRM) and Dell Storage Monitoring and Reporting (SMR)
- BIG-IP Next CNF Fluentd update for WEBrick
- Dell APEX Cloud Platform for Microsoft Azure update for third-party components
- Ubuntu update for ruby2.3
- SUSE update for ruby2.5