HTTP Request Smuggling (CL.0) leads to mass redirect users to attacker server without user interaction
High
L
LinkedIn
Submitted None
Team Summary
Official summary from LinkedIn
- Reporter detected HTTP Request Smuggling on a 3rd party CDN - Because the issue was with a specific 3rd party CDN, the impact on LinkedIn was limited because we use numerous different CDNs and it didn't affect our main site - LinkedIn worked with the specific CDN provider to get this resolved quickly
Actions:
Reported by
vampirex
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
HTTP Request Smuggling