CVE-2024-47522

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.7, invalid ALPN in TLS/QUIC traffic when JA4 matching/logging is enabled can lead to Suricata aborting with a panic. This issue has been addressed in 7.0.7. One may disable ja4 as a workaround.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*

History

22 Oct 2024, 13:51

Type Values Removed Values Added
References () https://github.com/OISF/suricata/security/advisories/GHSA-w5xv-6586-jpm7 - () https://github.com/OISF/suricata/security/advisories/GHSA-w5xv-6586-jpm7 - Mitigation, Third Party Advisory
References () https://redmine.openinfosecfoundation.org/issues/7267 - () https://redmine.openinfosecfoundation.org/issues/7267 - Issue Tracking, Vendor Advisory
First Time Oisf suricata
Oisf
CPE cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*

18 Oct 2024, 12:53

Type Values Removed Values Added
Summary
  • (es) Suricata es un sistema de detección de intrusiones, un sistema de prevención de intrusiones y un motor de monitoreo de seguridad de red. Antes de la versión 7.0.7, un ALPN no válido en el tráfico TLS/QUIC cuando la coincidencia/registro de JA4 está habilitado puede provocar que Suricata cancele la conexión con un mensaje de pánico. Este problema se ha solucionado en la versión 7.0.7. Se puede deshabilitar JA4 como workaround.

16 Oct 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-16 20:15

Updated : 2024-10-22 13:51


NVD link : CVE-2024-47522

Mitre link : CVE-2024-47522

CVE.ORG link : CVE-2024-47522


JSON object : View

Products Affected

oisf

  • suricata
CWE
CWE-617

Reachable Assertion