Inconsistent interpretation of HTTP requests in waitress - CVE-2024-49768
Published: November 1, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform HTTP request smuggling attacks.
The vulnerability exists due to improper validation of HTTP requests. A remote attacker can send a specially crafted HTTP request to the server and smuggle arbitrary HTTP headers.
Successful exploitation of vulnerability may allow an attacker to poison HTTP cache and perform phishing attacks.
Affected software
Storage Ceph
IBM Cloud Pak for Watson AIOps
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 15 SP4 LTSS
Python 3 Module
openSUSE Leap
Ubuntu
openEuler
Fedora
PowerVC
IBM Process Mining
Red Hat OpenStack
python3-waitress (Ubuntu package)
python3-waitress
python-waitress
python-waitress (Red Hat package)
python-waitress-help
mingw-python-waitress
python311-waitress-doc
python311-waitress
kata-containers (Red Hat package)
openshift (Red Hat package)
openshift-ansible (Red Hat package)
kernel-rt (Red Hat package)
Red Hat OpenShift Container Platform
How to mitigate CVE-2024-49768
PowerVC - addressed in versions 2.2.1.2, 2.3.0
Storage Ceph - update to 6.1z0
python3-waitress (Ubuntu package) - addressed in versions Ubuntu Pro, 1.4.1-1ubuntu0.2, 1.4.4-1.1ubuntu1.1, 3.0.0-1ubuntu0.1
IBM Process Mining - update to 1.15.0 IF004
python3-waitress - addressed in versions 2.0.0-4, 2.1.2-2
python-waitress - addressed in versions 2.0.0-4, 2.1.2-2
python-waitress (Red Hat package) - addressed in versions 2.0.0-4.el8ost, 2.0.0-4.el9ost, 3.0.1-1.el9
python-waitress-help - update to 2.1.2-2
mingw-python-waitress - update to 2.1.2-7.fc40
python311-waitress-doc - update to 2.1.2-150400.12.7.1
python311-waitress - update to 2.1.2-150400.12.7.1
python-waitress - update to 3.0.1-1.fc41
kata-containers (Red Hat package) - addressed in versions 3.7.0-4.rhaos4.16.el9, 3.7.0-4.rhaos4.17.el9
IBM Cloud Pak for Watson AIOps - update to 4.8.0
openshift (Red Hat package) - addressed in versions 4.12.0-202411110730.p0.g1eb8682.assembly.stream.el8, 4.12.0-202411110730.p0.g1eb8682.assembly.stream.el9, 4.13.0-202411110736.p0.g53fd427.assembly.stream.el8, 4.13.0-202411110736.p0.g53fd427.assembly.stream.el9, 4.14.0-202411110739.p0.g03a907c.assembly.stream.el8, 4.14.0-202411110739.p0.g03a907c.assembly.stream.el9, 4.16.0-202411111337.p0.g7423cac.assembly.stream.el8, 4.16.0-202411111337.p0.g7423cac.assembly.stream.el9, 4.17.0-202411070335.p0.g82afd77.assembly.stream.el8, 4.17.0-202411070335.p0.g82afd77.assembly.stream.el9
Red Hat OpenShift Container Platform - addressed in versions 4.12.70, 4.12.72, 4.13.54, 4.14.41, 4.15.39, 4.16.23, 4.17.5
openshift-ansible (Red Hat package) - addressed in versions 4.17.0-202411120704.p0.g5c737da.assembly.stream.el8, 4.17.0-202411120704.p0.g5c737da.assembly.stream.el9
kernel-rt (Red Hat package) - update to 4.18.0-372.131.1.rt7.291.el8_6
Red Hat OpenStack - addressed in versions 16.2, 17.1
External References
Related Security Bulletins
- Multiple vulnerabilities in Waitress
- openEuler 22.03 LTS SP4 update for python-waitress
- openEuler 24.03 LTS update for python-waitress
- openEuler 22.03 LTS SP1 update for python-waitress
- openEuler 22.03 LTS SP3 update for python-waitress
- SUSE update for python-waitress
- Fedora 41 update for python-waitress
- Fedora 40 update for mingw-python-waitress
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Ubuntu update for waitress
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16 packages
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14 packages
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15 packages
- Multiple vulnerabilities in IBM Process Mining
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13 packages
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Multiple vulnerabilities in Red Hat OpenStack 16.2 packages
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat OpenStack 17.1 packages
- Multiple vulnerabilities in Red Hat OpenStack 17.1 packages
- IBM PowerVC update for Waitress
- IBM Storage Ceph update for python-waitress