Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-31079

Опубликовано: 29 мая 2024
Источник: ubuntu
Приоритет: medium
CVSS3: 4.8

Описание

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate or cause other potential impact. This attack requires that a request be specifically timed during the connection draining process, which the attacker has no visibility and limited influence over.

РелизСтатусПримечание
devel

not-affected

code not present
esm-infra-legacy/trusty

not-affected

code not present
esm-infra/bionic

not-affected

code not present
esm-infra/focal

not-affected

code not present
esm-infra/xenial

not-affected

code not present
focal

not-affected

code not present
jammy

not-affected

code not present
mantic

not-affected

code not present
noble

not-affected

code not present
trusty/esm

not-affected

code not present

Показывать по

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
redhat
около 1 года назад

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate or cause other potential impact. This attack requires that a request be specifically timed during the connection draining process, which the attacker has no visibility and limited influence over.

CVSS3: 4.8
nvd
около 1 года назад

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate or cause other potential impact. This attack requires that a request be specifically timed during the connection draining process, which the attacker has no visibility and limited influence over.

CVSS3: 4.8
debian
около 1 года назад

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC mod ...

CVSS3: 6.5
fstec
около 1 года назад

Уязвимость модуля HTTP/3 QUIC (ngx_http_v3_module) веб-серверов NGINX Plus и NGINX OSS, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
redos
11 месяцев назад

Множественные уязвимости nginx

4.8 Medium

CVSS3

Уязвимость CVE-2024-31079