Описание
NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.
Ссылки
- Mailing ListThird Party Advisory
- MitigationRelease NotesVendor Advisory
- Mailing ListThird Party Advisory
- ExploitMitigationThird Party Advisory
- Release NotesThird Party Advisory
- PatchThird Party Advisory
- PatchVendor Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Mailing ListThird Party Advisory
- MitigationRelease NotesVendor Advisory
- Mailing ListThird Party Advisory
- ExploitMitigationThird Party Advisory
- Release NotesThird Party Advisory
- PatchThird Party Advisory
- PatchVendor Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
EPSS
5.3 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
Связанные уязвимости
NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.
NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.
NGINX before 1.17.7, with certain error_page configurations, allows HT ...
EPSS
5.3 Medium
CVSS3
4.3 Medium
CVSS2