Security Advisory

CVE-2024-10264

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-03-20 10:10:04
Last updated 2025-03-20 18:31:45
Assigner @huntr_ai
State PUBLISHED

Description

HTTP Request Smuggling vulnerability in netease-youdao/qanything version 1.4.1 allows attackers to exploit inconsistencies in the interpretation of HTTP requests between a proxy and a server. This can lead to unauthorized access, bypassing security controls, session hijacking, data leakage, and potentially arbitrary code execution.