CVE Published: 02/05/2024 |
CVE Updated: 02/08/2024 |
CVE Year: 2024 Source: apache |
Vendor: Apache Software Foundation |
Product: Apache APISIX Status : PUBLISHED
CVE-2024-32638 Description
Inconsistent Interpretation of HTTP Requests (\'HTTP Request Smuggling\') vulnerability in Apache APISIX when using `forward-auth` plugin.This issue affects Apache APISIX: from 3.8.0, 3.9.0.
Users are recommended to upgrade to version 3.8.1, 3.9.1 or higher, which fixes the issue.