UBUNTU-CVE-2024-1135

Source
https://ubuntu.com/security/CVE-2024-1135
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-1135.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2024-1135
Related
Published
2024-04-16T00:15:00Z
Modified
2024-10-15T14:12:49Z
Summary
[none]
Details

Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability allows for a range of attacks including cache poisoning, session manipulation, and data exposure.

References

Affected packages

Ubuntu:Pro:14.04:LTS / gunicorn

Package

Name
gunicorn
Purl
pkg:deb/ubuntu/gunicorn?arch=src?distro=trusty/esm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

17.*

17.5-2
17.5-2build1
17.5-2ubuntu0.1~esm1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:16.04:LTS / gunicorn

Package

Name
gunicorn
Purl
pkg:deb/ubuntu/gunicorn?arch=src?distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

19.*

19.0-8ubuntu1
19.4.1-1ubuntu1
19.4.5-1ubuntu1
19.4.5-1ubuntu1.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:18.04:LTS / gunicorn

Package

Name
gunicorn
Purl
pkg:deb/ubuntu/gunicorn?arch=src?distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

19.*

19.7.1-3
19.7.1-4

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / gunicorn

Package

Name
gunicorn
Purl
pkg:deb/ubuntu/gunicorn?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

19.*

19.9.0-1
19.9.0-4

20.*

20.0.0-1
20.0.2-1
20.0.4-1
20.0.4-2
20.0.4-3

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / gunicorn

Package

Name
gunicorn
Purl
pkg:deb/ubuntu/gunicorn?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

20.*

20.1.0-1
20.1.0-2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.10 / gunicorn

Package

Name
gunicorn
Purl
pkg:deb/ubuntu/gunicorn?arch=src?distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

20.*

20.1.0-6

22.*

22.0.0-1

23.*

23.0.0-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / gunicorn

Package

Name
gunicorn
Purl
pkg:deb/ubuntu/gunicorn?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

20.*

20.1.0-6

Ecosystem specific

{
    "ubuntu_priority": "medium"
}