CVE-2024-52530

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Nov 11, 2024
Updated: Nov 12, 2024
CWE ID 444

Summary

CVE-2024-52530 is a vulnerability affecting GNOME libsoup before version 3.6.0. This issue allows for HTTP request smuggling in certain configurations due to the library's mishandling of '\0' characters at the end of header names. A malicious actor can exploit this flaw to inject malicious headers or modify existing ones, potentially leading to unintended data transfer or unauthorized access. This vulnerability poses a serious risk to systems running affected versions of GNOME libsoup. It is strongly recommended that users upgrade to the latest version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share