CVE-2024-31617: Medium severity openlitespeed vulnerability
Published May 22, 2024
·Updated
OpenLiteSpeed before 1.8.1 mishandles chunked encoding.
Affected Software
2 affected components
Litespeedtech Openlitespeed<1.8.1
LiteSpeed OpenLiteSpeed<1.8.1
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 22, 2024
CVE Published
via NVD·06:15 PM
Nov 19, 2024
Data Sourced
via MITRE·07:37 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-31617?
CVE-2024-31617 is rated as a medium severity vulnerability due to its potential to allow denial of service attacks.
2
How do I fix CVE-2024-31617?
To mitigate CVE-2024-31617, upgrade to OpenLiteSpeed version 1.8.1 or later.
3
What software is affected by CVE-2024-31617?
CVE-2024-31617 affects OpenLiteSpeed versions prior to 1.8.1.
4
What type of vulnerability is CVE-2024-31617?
CVE-2024-31617 is a vulnerability related to improper handling of chunked encoding in OpenLiteSpeed.
5
Is CVE-2024-31617 actively exploited?
As of now, there is no public indication that CVE-2024-31617 is actively exploited in the wild.