CVE-2024-9622

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Oct 8, 2024
Updated: Oct 10, 2024
CWE ID 444

Summary

CVE-2024-9622 is a newly discovered vulnerability affecting the resteasy-netty4 library. The issue stems from a failure to properly manage HTTP requests utilizing smuggling techniques. When an HTTP smuggling request containing an ASCII control character is received, the Netty HttpObjectDecoder transitions into a BAD_MESSAGE state. Consequently, any subsequent legitimate requests on the same connection are disregarded, resulting in client timeouts. This condition can impact systems using load balancers and potentially expose them to further risks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share