Описание
When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 1.30.1-4ubuntu1 |
| esm-infra-legacy/trusty | not-affected | |
| esm-infra-legacy/xenial | not-affected | |
| esm-infra/bionic | not-affected | |
| esm-infra/focal | not-affected | |
| esm-infra/xenial | ignored | end of ESM support, was needs-triage |
| jammy | not-affected | |
| noble | not-affected | 1.24.0-2ubuntu7.8 |
| questing | released | 1.28.0-6ubuntu1.4 |
| resolute | released | 1.28.3-2ubuntu1.2 |
Показывать по
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 ...
When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
EPSS
6.5 Medium
CVSS3