First published: Wed Apr 17 2024(Updated: )
Malformed headers can lead to HTTP request smuggling. Specifically, if a space is placed before a content-length header, it is not interpreted correctly, enabling attackers to smuggle in a second request within the body of the first. This vulnerability affects all users in all active release lines: 18.x, 20.x and, 21.x. <a href="https://nodejs.org/en/blog/vulnerability/april-2024-security-releases">https://nodejs.org/en/blog/vulnerability/april-2024-security-releases</a>
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Analytics | <=12.0.0-12.0.3 | |
IBM Cognos Analytics | <=11.2.0-11.2.4 FP4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-27982 is considered a high severity vulnerability due to its potential for HTTP request smuggling.
To fix CVE-2024-27982, users should apply the relevant patches provided for IBM Cognos Analytics.
CVE-2024-27982 affects all versions of IBM Cognos Analytics up to and including 12.0.3 and 11.2.4 FP4.
CVE-2024-27982 enables attackers to perform HTTP request smuggling through malformed headers.
There is no documented workaround for CVE-2024-27982; applying the patch is the recommended action.