Lucene search

K
ubuntucveUbuntu.comUB:CVE-2024-23829
HistoryJan 29, 2024 - 12:00 a.m.

CVE-2024-23829

2024-01-2900:00:00
ubuntu.com
ubuntu.com
8
aiohttp
http parser
version 3.9.2
security-sensitive
request smuggling
error handling
internet standards
injection
incomplete fix
resource consumption

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

6.8 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

31.6%

aiohttp is an asynchronous HTTP client/server framework for asyncio and
Python. Security-sensitive parts of the Python HTTP parser retained minor
differences in allowable character sets, that must trigger error handling
to robustly match frame boundaries of proxies in order to protect against
injection of additional requests. Additionally, validation could trigger
exceptions that were not handled consistently with processing of other
malformed input. Being more lenient than internet standards require could,
depending on deployment environment, assist in request smuggling. The
unhandled exception could cause excessive resource consumption on the
application server and/or its logging facilities. This vulnerability exists
due to an incomplete fix for CVE-2023-47627. Version 3.9.2 fixes this
vulnerability.

Notes

Author Note
tyhicks mozjs contains a copy of the SpiderMonkey JavaScript engine
mdeslaur starting with Ubuntu 22.04, the firefox package is just a script that installs the Firefox snap

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

6.8 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

31.6%