HTTP Request Smuggling,Browser-Powered Desync Attacks SharePoint 2019

Srinivasulu Batcha [External] 6 Reputation points
2022-10-28T04:05:12.67+00:00

The server appears to be vulnerable to client-side desync attacks. A POST request was sent to the path'/' with a second request sent as the body. The server ignored the Content-Length header and did not close the connection, leading to the smuggled request being interpreted as the next request.

CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request Sm...
CAPEC-33: HTTP Request Smuggling

We have configured the SharePoint 2019 newly and WFE's placed in DMZ and Application servers are in Internal Domain.

Can you please suggest the Mitigation plans for this ?

Microsoft 365 and Office SharePoint Server For business
Microsoft 365 and Office SharePoint Development
{count} vote

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.