CVE-2024-6827
CVSS 3.0 Score 7.5 of 10 (high)
Details
Summary
CVE-2024-6827 is a newly disclosed vulnerability affecting Gunicorn version 21.2.0. The issue lies in the application's failure to adhere to RFC standards when validating the 'Transfer-Encoding' header. This oversight enables TE.CL request smuggling, which can result in various attack vectors such as cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse. Attackers can potentially inject malicious requests, causing unintended server behavior and potential data breaches. It is strongly recommended to update to a patched version of Gunicorn to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Gunicorn
Affected Vendors
- Gunicorn Developer