Описание
When NGINX Open Source is configured to proxy HTTP/2 traffic by setting proxy_http_version to 2, and also uses proxy_set_body, an attacker may be able to inject frame headers and payload bytes to the upstream peer. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 1.30.1-4ubuntu1 |
| esm-infra-legacy/trusty | not-affected | code not present |
| esm-infra-legacy/xenial | not-affected | code not present |
| esm-infra/bionic | not-affected | code not present |
| esm-infra/focal | not-affected | code not present |
| esm-infra/xenial | ignored | end of ESM support, was needs-triage |
| jammy | not-affected | code not present |
| noble | not-affected | code not present |
| questing | not-affected | code not present |
| resolute | not-affected | code not present |
Показывать по
EPSS
5.8 Medium
CVSS3
Связанные уязвимости
When NGINX Open Source is configured to proxy HTTP/2 traffic by setting proxy_http_version to 2, and also uses proxy_set_body, an attacker may be able to inject frame headers and payload bytes to the upstream peer. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
When NGINX Open Source is configured to proxy HTTP/2 traffic by settin ...
When NGINX Open Source is configured to proxy HTTP/2 traffic by setting proxy_http_version to 2, and also uses proxy_set_body, an attacker may be able to inject frame headers and payload bytes to the upstream peer. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Уязвимость модуля ngx_http_proxy_v2_module веб-серверов NGINX Open Source, позволяющая нарушителю оказать воздействие на целостность защищаемой информации
EPSS
5.8 Medium
CVSS3