http/modules/ngx_http_proxy_module.c in nginx 1.1.4 through 1.2.8 and 1.3.0 through 1.4.0, when proxy_pass is used with untrusted HTTP servers, allows remote attackers to cause a denial of service (crash) and obtain sensitive information from worker process memory via a crafted proxy response, a similar vulnerability to CVE-2013-2028.
CVSS Details
- CVSS 3.1 Base Score: 8.2
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade nginx | Jul 30, 2024 | Jul 20, 2013 |
| Freebsd | — | Upgrade nginxUpgrade nginx-devel | Dec 10, 2025 | May 7, 2013 |
| Gentoo Linux | — | Upgrade www-servers/nginx. | Oct 30, 2017 | Jul 19, 2013 |
| Nginx | — | Upgrade to nginx version 1.5.0Upgrade to nginx version 1.4.1Upgrade to nginx version 1.2.9 | Jan 27, 2014 | Jul 18, 2013 |
| Suse | — | Upgrade nginx | Dec 12, 2013 | Jul 19, 2013 |
| Ubuntu | — | Upgrade nginx | Nov 19, 2024 | Jul 20, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub