Rewterz
Multiple SAP Products Vulnerabilities
May 3, 2024
Rewterz
Sidewinder APT Campaign Uses Phishing Document to Target Pakistan Prime Minister’s Office and MOFA – Active IOCs
May 4, 2024

CVE-2024-32638 – Apache APISIX Vulnerability

Severity

Medium

Analysis Summary

CVE-2024-32638

Apache APISIX is vulnerable to HTTP request smuggling, caused by a flaw when using forward-auth plugin. By sending a specially crafted request, an attacker could exploit this vulnerability to poison the web cache, bypass web application firewall protection, and conduct XSS attacks.

Impact

  • Gain Access

Indicators of Compromise

CVE

  • CVE-2024-32638

Affected Vendors

Apache

Affected Products

  • Apache APISIX 3.8.0
  • Apache APISIX 3.9.0

Remediation

Upgrade to the latest version of Apache APISIX, available from the Apache Website.

Apache Website