Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-20372

Опубликовано: 09 янв. 2020
Источник: debian

Описание

NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
nginxfixed1.16.1-3package
nginxfixed1.14.2-2+deb10u2busterpackage
nginxfixed1.10.3-1+deb9u4stretchpackage
nginxno-dsajessiepackage

Примечания

  • https://bertjwregeer.keybase.pub/2019-12-10%20-%20error_page%20request%20smuggling.pdf

  • https://github.com/nginx/nginx/commit/c1be55f97211d38b69ac0c2027e6812ab8b1b94e

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 6 лет назад

NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.

CVSS3: 5.3
redhat
около 6 лет назад

NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.

CVSS3: 5.3
nvd
около 6 лет назад

NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.

CVSS3: 5.3
msrc
больше 5 лет назад

Описание отсутствует

suse-cvrf
почти 6 лет назад

Security update for nginx