CVE-2024-52530: High severity IBM Edge Application Manager vulnerability
GNOME libsoup before 3.6.0 allows HTTP request smuggling in some configurations
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libsoup3to a version that resolves this vulnerability.Fixed in 3.6.1-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.0.4-2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.4.4-2 - Upgrade
Upgrade
GNOME libsoupto a version that resolves this vulnerability.Fixed in 3.6.0
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52530?
CVE-2024-52530 is classified as a critical vulnerability due to its potential for HTTP request smuggling.
How do I fix CVE-2024-52530?
To fix CVE-2024-52530, upgrade to libsoup version 3.6.1-1 or later.
Which versions of libsoup are affected by CVE-2024-52530?
CVE-2024-52530 affects libsoup versions prior to 3.6.0, particularly libsoup2.4 and libsoup3 versions up to 3.2.2-2.
Is CVE-2024-52530 applicable to Debian users?
Yes, Debian users running affected versions of libsoup should upgrade to mitigate CVE-2024-52530.
What type of attack can CVE-2024-52530 facilitate?
CVE-2024-52530 can facilitate HTTP request smuggling attacks, potentially allowing malicious requests to bypass security controls.