Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, the rules inspecting HTTP2 headers can get bypassed by crafted traffic. The vulnerability has been patched in 7.0.3.
References
Configurations
History
19 Dec 2024, 19:30
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-noinfo | |
CPE | cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* |
|
First Time |
Oisf
Fedoraproject fedora Oisf suricata Fedoraproject |
|
References | () https://github.com/OISF/suricata/commit/478a2a38f54e2ae235f8486bff87d7d66b6307f0 - Patch | |
References | () https://github.com/OISF/suricata/security/advisories/GHSA-gv29-5hqw-5h8c - Vendor Advisory | |
References | () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GOCOBFUTIFHOP2PZOH4ENRFXRBHIRKK4/ - Mailing List | |
References | () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZXJIT7R53ZXROO3I256RFUWTIW4ECK6P/ - Mailing List | |
References | () https://redmine.openinfosecfoundation.org/issues/6717 - Issue Tracking |
Information
Published : 2024-02-26 16:27
Updated : 2024-12-19 19:30
NVD link : CVE-2024-24568
Mitre link : CVE-2024-24568
CVE.ORG link : CVE-2024-24568
JSON object : View
Products Affected
oisf
- suricata
fedoraproject
- fedora
CWE