CVE-2024-32638: Apache APISIX: Forward-Auth Request Smuggling
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Apache APISIX when using forward-auth plugin.This issue affects Apache APISIX: from 3.8.0, 3.9.0.
Users are recommended to upgrade to version 3.8.1, 3.9.1 or higher, which fixes the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32638?
CVE-2024-32638 is classified as a high severity vulnerability due to its potential for HTTP request smuggling.
How do I fix CVE-2024-32638?
To fix CVE-2024-32638, upgrade to Apache APISIX version 3.8.1, 3.9.1 or higher.
What versions of Apache APISIX are affected by CVE-2024-32638?
Apache APISIX versions prior to 3.8.1 and 3.9.1 are affected by CVE-2024-32638.
What components are impacted by CVE-2024-32638?
CVE-2024-32638 specifically impacts the 'forward-auth' plugin in Apache APISIX.
What is HTTP request smuggling in relation to CVE-2024-32638?
HTTP request smuggling refers to the vulnerability where malicious HTTP requests can be interpreted inconsistently by different components, leading to potentially harmful exploits.