Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-20372

Опубликовано: 09 янв. 2020
Источник: ubuntu
Приоритет: medium
CVSS2: 4.3
CVSS3: 5.3

Описание

NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.

РелизСтатусПримечание
bionic

released

1.14.0-0ubuntu1.7
devel

not-affected

1.17.7-0ubuntu1
disco

released

1.15.9-0ubuntu1.2
eoan

released

1.16.1-0ubuntu2.1
esm-infra-legacy/trusty

released

1.4.6-1ubuntu3.9+esm1
esm-infra/bionic

released

1.14.0-0ubuntu1.7
esm-infra/xenial

released

1.10.3-0ubuntu0.16.04.5
precise/esm

DNE

trusty

ignored

end of standard support
trusty/esm

released

1.4.6-1ubuntu3.9+esm1

Показывать по

4.3 Medium

CVSS2

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
redhat
около 6 лет назад

NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.

CVSS3: 5.3
nvd
около 6 лет назад

NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.

CVSS3: 5.3
msrc
больше 5 лет назад

Описание отсутствует

CVSS3: 5.3
debian
около 6 лет назад

NGINX before 1.17.7, with certain error_page configurations, allows HT ...

suse-cvrf
почти 6 лет назад

Security update for nginx

4.3 Medium

CVSS2

5.3 Medium

CVSS3