PT-2024-6627 · Loway · Queuemetrics

Published

2024-09-03

·

Updated

2024-09-11

·

CVE-2024-42342

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Loway QueueMetrics (affected versions not specified)
Description: The issue is related to inconsistent interpretation of HTTP requests, which can be exploited by a remote attacker to bypass existing security restrictions and perform an HTTP request smuggling attack. This type of attack can allow an attacker to manipulate the HTTP requests and responses, potentially leading to unauthorized access or other malicious activities.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

HTTP Request/Response Smuggling

Weakness Enumeration

Related Identifiers

BDU:2024-07786
CVE-2024-42342

Affected Products

Queuemetrics