PT-2024-12217 · Menlosecurity · Menlo On-Premise Appliance

Published

2024-12-14

·

Updated

2024-12-19

·

CVE-2023-29476

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Menlo On-Premise Appliance versions prior to 2.88 Menlo On-Premise Appliance versions 2.88 through 2.88.1 Menlo On-Premise Appliance versions 2.89 through 2.89.0 Menlo On-Premise Appliance versions 2.90 through 2.90.0
Description The web policy may not be consistently applied properly to intentionally malformed client requests. This issue is fixed in versions 2.88.2+, 2.89.1+, and 2.90.1+.
Recommendations For Menlo On-Premise Appliance versions prior to 2.88, update to version 2.88.2 or later. For Menlo On-Premise Appliance versions 2.88 through 2.88.1, update to version 2.88.2 or later. For Menlo On-Premise Appliance versions 2.89 through 2.89.0, update to version 2.89.1 or later. For Menlo On-Premise Appliance versions 2.90 through 2.90.0, update to version 2.90.1 or later.

Fix

HTTP Request/Response Smuggling

Weakness Enumeration

Related Identifiers

CVE-2023-29476

Affected Products

Menlo On-Premise Appliance