Inconsistent interpretation of HTTP requests in waitress - CVE-2024-49768

 

Inconsistent interpretation of HTTP requests in waitress - CVE-2024-49768

Published: November 1, 2024


Vulnerability identifier: #VU99613
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-49768
CWE-ID: CWE-444
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform HTTP request smuggling attacks.

The vulnerability exists due to improper validation of HTTP requests. A remote attacker can send a specially crafted HTTP request to the server and smuggle arbitrary HTTP headers.

Successful exploitation of vulnerability may allow an attacker to poison HTTP cache and perform phishing attacks.


Affected software

waitress
Storage Ceph
IBM Cloud Pak for Watson AIOps
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 15 SP4 LTSS
Python 3 Module
openSUSE Leap
Ubuntu
openEuler
Fedora
PowerVC
IBM Process Mining
Red Hat OpenStack
python3-waitress (Ubuntu package)
python3-waitress
python-waitress
python-waitress (Red Hat package)
python-waitress-help
mingw-python-waitress
python311-waitress-doc
python311-waitress
kata-containers (Red Hat package)
openshift (Red Hat package)
openshift-ansible (Red Hat package)
kernel-rt (Red Hat package)
Red Hat OpenShift Container Platform

How to mitigate CVE-2024-49768

Install updates from vendor's website.

waitress - update to 3.0.1
PowerVC - addressed in versions 2.2.1.2, 2.3.0
Storage Ceph - update to 6.1z0
python3-waitress (Ubuntu package) - addressed in versions Ubuntu Pro, 1.4.1-1ubuntu0.2, 1.4.4-1.1ubuntu1.1, 3.0.0-1ubuntu0.1
IBM Process Mining - update to 1.15.0 IF004
python3-waitress - addressed in versions 2.0.0-4, 2.1.2-2
python-waitress - addressed in versions 2.0.0-4, 2.1.2-2
python-waitress (Red Hat package) - addressed in versions 2.0.0-4.el8ost, 2.0.0-4.el9ost, 3.0.1-1.el9
python-waitress-help - update to 2.1.2-2
mingw-python-waitress - update to 2.1.2-7.fc40
python311-waitress-doc - update to 2.1.2-150400.12.7.1
python311-waitress - update to 2.1.2-150400.12.7.1
python-waitress - update to 3.0.1-1.fc41
kata-containers (Red Hat package) - addressed in versions 3.7.0-4.rhaos4.16.el9, 3.7.0-4.rhaos4.17.el9
IBM Cloud Pak for Watson AIOps - update to 4.8.0
openshift (Red Hat package) - addressed in versions 4.12.0-202411110730.p0.g1eb8682.assembly.stream.el8, 4.12.0-202411110730.p0.g1eb8682.assembly.stream.el9, 4.13.0-202411110736.p0.g53fd427.assembly.stream.el8, 4.13.0-202411110736.p0.g53fd427.assembly.stream.el9, 4.14.0-202411110739.p0.g03a907c.assembly.stream.el8, 4.14.0-202411110739.p0.g03a907c.assembly.stream.el9, 4.16.0-202411111337.p0.g7423cac.assembly.stream.el8, 4.16.0-202411111337.p0.g7423cac.assembly.stream.el9, 4.17.0-202411070335.p0.g82afd77.assembly.stream.el8, 4.17.0-202411070335.p0.g82afd77.assembly.stream.el9
Red Hat OpenShift Container Platform - addressed in versions 4.12.70, 4.12.72, 4.13.54, 4.14.41, 4.15.39, 4.16.23, 4.17.5
openshift-ansible (Red Hat package) - addressed in versions 4.17.0-202411120704.p0.g5c737da.assembly.stream.el8, 4.17.0-202411120704.p0.g5c737da.assembly.stream.el9
kernel-rt (Red Hat package) - update to 4.18.0-372.131.1.rt7.291.el8_6
Red Hat OpenStack - addressed in versions 16.2, 17.1

External References

Related Security Bulletins