PT-2024-7028 · Unknown+2 · Resteasy-Netty4+2
Txema-Martinez-Scopely
·
Published
2024-10-07
·
Updated
2025-07-10
·
CVE-2024-9622
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
resteasy-netty4 library (affected versions not specified)
Description
A vulnerability was found in the resteasy-netty4 library arising from improper handling of HTTP requests using smuggling techniques. When an HTTP smuggling request with an ASCII control character is sent, it causes the Netty HttpObjectDecoder to transition into a BAD MESSAGE state. As a result, any subsequent legitimate requests on the same connection are ignored, leading to client timeouts. This issue may impact systems using load balancers and expose them to risk. The vulnerability can be exploited by a remote attacker to send hidden HTTP requests, also known as HTTP Request Smuggling attacks.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
HTTP Request/Response Smuggling
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Ubuntu
Resteasy-Netty4