HTTP Request Smuggling Affecting olcne-agent package, versions <0:1.5.12-6.el7
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-ORACLE7-OLCNEAGENT-6593637
- published 10 Apr 2024
- disclosed 4 Apr 2023
Introduced: 4 Apr 2023
CVE-2023-27491 Open this link in a new tabHow to fix?
Upgrade Oracle:7 olcne-agent to version 0:1.5.12-6.el7 or higher.
This issue was patched in ELSA-2023-12357.
NVD Description
Note: Versions mentioned in the description apply only to the upstream olcne-agent package and not the olcne-agent package as distributed by Oracle.
See How to fix? for Oracle:7 relevant fixed versions and status.
Envoy is an open source edge and service proxy designed for cloud-native applications. Compliant HTTP/1 service should reject malformed request lines. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, There is a possibility that non compliant HTTP/1 service may allow malformed requests, potentially leading to a bypass of security policies. This issue is fixed in versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9.
References
- https://linux.oracle.com/cve/CVE-2023-27491.html
- https://linux.oracle.com/errata/ELSA-2023-12354.html
- https://linux.oracle.com/errata/ELSA-2023-12355.html
- https://linux.oracle.com/errata/ELSA-2023-12356.html
- https://linux.oracle.com/errata/ELSA-2023-12357.html
- https://linux.oracle.com/errata/ELSA-2023-23649.html
- https://datatracker.ietf.org/doc/html/rfc9113#section-8.3
- https://datatracker.ietf.org/doc/html/rfc9114#section-4.3.1
- https://github.com/envoyproxy/envoy/security/advisories/GHSA-5jmv-cw9p-f9rp
- https://www.rfc-editor.org/rfc/rfc9110#section-5.6.2