cbcvebase.
CVE-2024-9622
published 2024-10-08

CVE-2024-9622: A vulnerability was found in the resteasy-netty4 library arising from improper handling of HTTP requests using smuggling techniques. When an HTTP smuggling…

PriorityP428medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.65%
47.0th percentile
A vulnerability was found in the resteasy-netty4 library arising from improper handling of HTTP requests using smuggling techniques. When an HTTP smuggling request with an ASCII control character is sent, it causes the Netty HttpObjectDecoder to transition into a BAD_MESSAGE state. As a result, any subsequent legitimate requests on the same connection are ignored, leading to client timeouts, which may impact systems using load balancers and expose them to risk.

Affected

4 ranges
VendorProductVersion rangeFixed in
redhatresteasy>= 0 < 3.0.6-3ubuntu0.1~esm13.0.6-3ubuntu0.1~esm1
redhatresteasy>= 0 < 3.6.2-2ubuntu0.20.04.1~esm13.6.2-2ubuntu0.20.04.1~esm1
redhatresteasy>= 0 < 3.6.2-2ubuntu0.22.04.1~esm13.6.2-2ubuntu0.22.04.1~esm1
redhatresteasy>= 0 < 3.6.2-2ubuntu0.24.04.1~esm13.6.2-2ubuntu0.24.04.1~esm1

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
osv6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.