CVE-2024-27982: Medium severity IBM Cognos Analytics vulnerability
Malformed headers can lead to HTTP request smuggling. Specifically, if a space is placed before a content-length header, it is not interpreted correctly, enabling attackers to smuggle in a second request within the body of the first.
This vulnerability affects all users in all active release lines: 18.x, 20.x and, 21.x.
https://nodejs.org/en/blog/vulnerability/april-2024-security-releases
Other sources
The team has identified a critical vulnerability in the http server of the most recent version of Node where malformed headers can lead to HTTP request smuggling. Specifically if a space is placed before a content-length header it is not interpreted correctly enabling attackers to smuggle in a second request within the body of the first.
— Microsoft
The team has identified a critical vulnerability in the http server of the most recent version of Node, where malformed headers can lead to HTTP request smuggling. Specifically, if a space is placed before a content-length header, it is not interpreted correctly, enabling attackers to smuggle in a second request within the body of the first.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27982?
CVE-2024-27982 is considered a high severity vulnerability due to its potential for HTTP request smuggling.
How do I fix CVE-2024-27982?
To fix CVE-2024-27982, users should apply the relevant patches provided for IBM Cognos Analytics.
Which versions of IBM Cognos Analytics are affected by CVE-2024-27982?
CVE-2024-27982 affects all versions of IBM Cognos Analytics up to and including 12.0.3 and 11.2.4 FP4.
What type of attack does CVE-2024-27982 enable?
CVE-2024-27982 enables attackers to perform HTTP request smuggling through malformed headers.
Is there a workaround for CVE-2024-27982?
There is no documented workaround for CVE-2024-27982; applying the patch is the recommended action.