60 lines
2.4 KiB
JSON
Raw Normal View History

{
"id": "CVE-2024-6827",
"sourceIdentifier": "security@huntr.dev",
"published": "2025-03-20T10:15:33.357",
"lastModified": "2025-03-20T10:15:33.357",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse."
},
{
"lang": "es",
"value": "La versi\u00f3n 21.2.0 de Gunicorn no valida correctamente el valor del encabezado \"Transfer-Encoding\" seg\u00fan lo especificado en los est\u00e1ndares RFC, lo que lleva al m\u00e9todo de respaldo predeterminado \"Content-Length\", lo que la hace vulnerable al contrabando de solicitudes TE.CL. Esta vulnerabilidad puede provocar envenenamiento de cach\u00e9, exposici\u00f3n de datos, manipulaci\u00f3n de sesiones, SSRF, XSS, denegaci\u00f3n de servicio (DoS), vulneraci\u00f3n de la integridad de los datos, elusi\u00f3n de seguridad, fuga de informaci\u00f3n y abuso de la l\u00f3gica de negocio."
}
],
"metrics": {
"cvssMetricV30": [
{
"source": "security@huntr.dev",
"type": "Secondary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 3.9,
"impactScore": 3.6
}
]
},
"weaknesses": [
{
"source": "security@huntr.dev",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-444"
}
]
}
],
"references": [
{
"url": "https://huntr.com/bounties/1b4f8f38-39da-44b6-9f98-f618639d0dd7",
"source": "security@huntr.dev"
}
]
}