PT-2025-11679 · Openresty+1 · Openresty+2
CVE-2024-33452
·
Publicado
2025-03-09
·
Atualizado
2025-06-24
CVSS v3.1
7.7
Alta
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
OpenResty/lua-nginx-module (affected versions not specified)
Description
The issue concerns HTTP Request Smuggling in HEAD requests. When handling HTTP/1.1 requests, the lua-nginx-module incorrectly parses HEAD requests with a body, treating the request body as a new, separate request. This can lead to desynchronization of proxy servers in a chain. Proxy servers using the lua-nginx-module, such as Kong Gateway and Apache APISIX, are vulnerable to this attack. An attacker can exploit this to inject malicious responses, bypass front-proxy protection, or steal other users' responses.
Technical details about exploitation include:
- API Endpoints: Such as
/app/assetsor/admin. - Vulnerable Parameters or Variables: Such as
Content-LengthorHost. - Function Names: Not explicitly mentioned.
The estimated number of potentially affected devices worldwide is not provided. However, the issue can be exploited in real-world scenarios, such as injecting XSS attacks or bypassing Cloudflare protection.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
HTTP Request/Response Smuggling
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Debian
Openresty
Lua-Nginx-Module