PT-2025-11679 · Openresty+1 · Openresty+2

CVE-2024-33452

·

Publicado

2025-03-09

·

Atualizado

2025-06-24

CVSS v3.1

7.7

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions OpenResty/lua-nginx-module (affected versions not specified)
Description The issue concerns HTTP Request Smuggling in HEAD requests. When handling HTTP/1.1 requests, the lua-nginx-module incorrectly parses HEAD requests with a body, treating the request body as a new, separate request. This can lead to desynchronization of proxy servers in a chain. Proxy servers using the lua-nginx-module, such as Kong Gateway and Apache APISIX, are vulnerable to this attack. An attacker can exploit this to inject malicious responses, bypass front-proxy protection, or steal other users' responses.
Technical details about exploitation include:
  • API Endpoints: Such as /app/assets or /admin.
  • Vulnerable Parameters or Variables: Such as Content-Length or Host.
  • Function Names: Not explicitly mentioned.
The estimated number of potentially affected devices worldwide is not provided. However, the issue can be exploited in real-world scenarios, such as injecting XSS attacks or bypassing Cloudflare protection.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

HTTP Request/Response Smuggling

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-04624
BIT-OPENRESTY-2024-33452
CVE-2024-33452
DLA-4228-1

Produtos afetados

Debian
Openresty
Lua-Nginx-Module