Multiple SAP Products Vulnerabilities
May 3, 2024Sidewinder APT Campaign Uses Phishing Document to Target Pakistan Prime Minister’s Office and MOFA – Active IOCs
May 4, 2024Multiple SAP Products Vulnerabilities
May 3, 2024Sidewinder APT Campaign Uses Phishing Document to Target Pakistan Prime Minister’s Office and MOFA – Active IOCs
May 4, 2024Severity
Medium
Analysis Summary
CVE-2024-32638
Apache APISIX is vulnerable to HTTP request smuggling, caused by a flaw when using forward-auth plugin. By sending a specially crafted request, an attacker could exploit this vulnerability to poison the web cache, bypass web application firewall protection, and conduct XSS attacks.
Impact
- Gain Access
Indicators of Compromise
CVE
- CVE-2024-32638
Affected Vendors
Affected Products
- Apache APISIX 3.8.0
- Apache APISIX 3.9.0
Remediation
Upgrade to the latest version of Apache APISIX, available from the Apache Website.