nginx 0.5.6 through 1.7.4, when using the same shared ssl_session_cache or ssl_session_ticket_key for multiple servers, can reuse a cached SSL session for an unrelated context, which allows remote attackers with certain privileges to conduct "virtual host confusion" attacks.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade nginx | Jul 30, 2024 | Dec 8, 2014 |
| Freebsd | — | Upgrade nginx-develUpgrade nginx | Dec 10, 2025 | Sep 16, 2014 |
| Gentoo Linux | — | Upgrade www-servers/nginx. | Oct 30, 2017 | Dec 8, 2014 |
| Nginx | — | Upgrade to nginx version 1.7.5Upgrade to nginx version 1.6.2 | Dec 8, 2014 | Dec 8, 2014 |
| Suse | — | Upgrade nginx | Feb 4, 2022 | Oct 13, 2014 |
| Ubuntu | — | Upgrade nginx-naxsiUpgrade nginx-coreUpgrade nginx-fullUpgrade nginx-extrasUpgrade nginx-light | Nov 8, 2024 | Dec 8, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub