medium

ALB HTTP request smuggling

Published Fri, Oct 4th, 2019

Platforms

aws

Summary

ALBs found vulnerable to HTTP request smuggling (desync attack).

Affected Services

ALB

Remediation

Configure setting on your ALBs

Tracked CVEs

No tracked CVEs

References

Contributed by https://github.com/0xdabbad00

Entry Status

Finalized

Disclosure Date

Fri, Oct 4th, 2019

Exploitability Period

-

Known ITW Exploitation

-

Detection Methods

None

Piercing Index Rating

-

Discovered by

James Kettle (Portswigger), Arkadiy Tetelman (Chime)