Published Fri, Oct 4th, 2019
Platforms
ALBs found vulnerable to HTTP request smuggling (desync attack).
ALB
Configure setting on your ALBs
No tracked CVEs
Contributed by https://github.com/0xdabbad00
Entry Status
Finalized
Disclosure Date
Fri, Oct 4th, 2019
Exploitability Period
-
Known ITW Exploitation
-
Detection Methods
None
Piercing Index Rating
-
Discovered by
James Kettle (Portswigger), Arkadiy Tetelman (Chime)