CVE-2024-10264
CVSS 3.0 Score 7.5 of 10 (high)
Details
Published Mar 20, 2025
CWE ID 444
Summary
CVE-2024-10264 is a newly disclosed HTTP Request Smuggling vulnerability affecting the netease-youdao/qanything software version 1.4.1. This issue arises from inconsistencies in how HTTP requests are interpreted between a proxy and a server. An attacker can exploit this vulnerability to gain unauthorized access, bypass security controls, hijack sessions, leak data, and potentially execute arbitrary code. The impact of this vulnerability can be severe, making it crucial for users to update their software as soon as a patch is available.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.