Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-6827— HTTP Request Smuggling in benoitc/gunicorn

AI Predicted 7.5 Difficulty: Moderate EPSS 0.77% · P53
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2024-6827

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
HTTP Request Smuggling in benoitc/gunicorn
Source: CVE Program / CVE List V5
Vulnerability Description
Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
HTTP请求的解释不一致性(HTTP请求私运)
Source: CVE Program / CVE List V5
Vulnerability Title
Gunicorn 环境问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Gunicorn是Gunicorn开源的一个 Python Web 服务器网关接口 HTTP 服务器。 Gunicorn 21.2.0版本存在环境问题漏洞,该漏洞源于Transfer-Encoding头验证不当,可能导致请求夹带攻击。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
benoitcbenoitc/gunicorn unspecified ~ latest -

II. Public POCs for CVE-2024-6827

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-6827

登录查看更多情报信息。

Vendor Advisories for CVE-2024-6827 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2024-6827

No comments yet


Leave a comment