CVE-2024-24568 Information

Description

Suricata is a network Intrusion Detection System Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3 the rules inspecting HTTP2 headers can get bypassed by crafted traffic. The vulnerability has been patched in 7.0.3.

Reference

https://github.com/OISF/suricata/security/advisories/GHSA-gv29-5hqw-5h8c https://github.com/OISF/suricata/commit/478a2a38f54e2ae235f8486bff87d7d66b6307f0 https://redmine.openinfosecfoundation.org/issues/6717

Share on: