VDB
BDU%3A2024-03553
BDU%3A2024-03553
PUBLISHED
CVSS 7.800000190734863 HIGH
Уязвимость WSGI-сервера gunicorn, связанная с недостатками обработки HTTP-запросов, позволяющая нарушителю обойти существующие ограничения безопасности и выполнить атаку «контрабанда HTTP-запросов»
Risk Scores
CVSS 2.0
7.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat Inc., Novell Inc., Сообщество свободного программного обеспечения, ООО «Ред Софт», АО «ИВК», АО "НППКТ" | Red Hat Enterprise Linux, OpenSUSE Leap, SUSE Linux Enterprise Server for SAP Applications, Debian GNU/Linux, Red Hat Storage, Red Hat Quay, Suse Linux Enterprise Server, РЕД ОС (запись в едином реестре российских программ №3751), Red Hat OpenShift Container Platform, Red Hat Satellite, Suse Linux Enterprise Desktop, Red Hat OpenStack Platform, Red Hat Update Infrastructure for Cloud Providers, Red Hat Discovery, Red Hat Ansible Automation Platform, АЛЬТ СП 10, gunicorn, ОСОН ОСнова Оnyx (запись в едином реестре российских программ №5913) |
Timeline
- May 7, 2024 CVE Published
- Aug 26, 2025 CVE Updated
References
- https://huntr.com/bounties/22158e34-cfd5-41ad-97e0-a780773d96c1 url
- https://github.com/benoitc/gunicorn/commit/ac29c9b0a758d21f1e0fb3b3457239e523fa9f1d url
- https://github.com/advisories/GHSA-w3h3-4rj7-4ph4 url
- https://github.com/benoitc/gunicorn/releases url
- https://www.suse.com/security/cve/CVE-2024-1135.html url
- https://access.redhat.com/security/cve/CVE-2024-1135 url
- https://security-tracker.debian.org/tracker/CVE-2024-1135 url
- https://поддержка.нппкт.рф/bin/view/ОСнова/Обновления/2.11/ url
- https://altsp.su/obnovleniya-bezopasnosti/ url
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ advisory