NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade nginx-mod-http-xslt-filterUpgrade nginx-filesystemUpgrade nginx-mod-streamUpgrade nginx-all-modulesUpgrade nginxUpgrade nginx-mod-http-image-filterUpgrade nginx-mod-mailUpgrade nginx-mod-http-perl | May 4, 2022 | Jan 9, 2020 |
| Alpine Linux | — | Upgrade nginx | Feb 11, 2020 | Jan 9, 2020 |
| Amazon Linux Ami 2 | — | Upgrade nginx-all-modulesUpgrade nginx-mod-http-image-filterUpgrade nginx-mod-mailUpgrade nginx-mod-http-xslt-filterUpgrade nginx-debuginfoUpgrade nginx-mod-http-perlUpgrade nginxUpgrade nginx-filesystemUpgrade nginx-mod-http-geoipUpgrade nginx-mod-stream | Sep 28, 2023 | Jan 9, 2020 |
| Centos_linux | — | Upgrade nginx-mod-mailUpgrade nginx-mod-http-image-filter-debuginfoUpgrade nginx-mod-http-perl-debuginfoUpgrade nginx-all-modulesUpgrade nginx-filesystemUpgrade nginx-mod-http-xslt-filter-debuginfoUpgrade nginxUpgrade nginx-mod-stream-debuginfoUpgrade nginx-mod-mail-debuginfoUpgrade nginx-mod-http-image-filterUpgrade nginx-mod-http-xslt-filterUpgrade nginx-debugsourceUpgrade nginx-mod-streamUpgrade nginx-debuginfoUpgrade nginx-mod-http-perl | Dec 21, 2020 | Jan 9, 2020 |
| Debian | — | Upgrade nginx | Jul 30, 2024 | Jan 9, 2020 |
| Freebsd | — | Upgrade nginxUpgrade nginx-devel | Feb 10, 2020 | Feb 9, 2020 |
| Huawei Euleros 2_0_sp2 | — | Upgrade nginx | Jun 17, 2020 | Jan 9, 2020 |
| Huawei Euleros 2_0_sp3 | — | Upgrade nginx | Apr 16, 2020 | Jan 9, 2020 |
| Huawei Euleros 2_0_sp5 | — | Upgrade nginxUpgrade nginx-mod-mailUpgrade nginx-all-modulesUpgrade nginx-filesystemUpgrade nginx-mod-http-xslt-filterUpgrade nginx-mod-http-perlUpgrade nginx-mod-http-image-filterUpgrade nginx-mod-stream | Feb 24, 2020 | Jan 9, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade nginx-mod-mailUpgrade nginx-mod-http-perlUpgrade nginx-mod-http-xslt-filterUpgrade nginx-all-modulesUpgrade nginx-mod-streamUpgrade nginx-mod-http-image-filterUpgrade nginxUpgrade nginx-filesystem | Feb 26, 2020 | Jan 9, 2020 |
| Nginx | — | Upgrade to nginx version 1.17.7 | Feb 10, 2023 | Jan 9, 2020 |
| Oracle_linux | — | Upgrade nginx-mod-streamUpgrade nginx-mod-http-xslt-filterUpgrade nginx-mod-http-image-filterUpgrade nginx-mod-http-perlUpgrade nginx-mod-mailUpgrade nginxUpgrade nginx-filesystemUpgrade nginx-all-modules | Dec 18, 2020 | Jan 9, 2020 |
| Redhat_linux | — | Upgrade nginx-mod-http-image-filter-debuginfoUpgrade nginx-mod-http-xslt-filterUpgrade nginx-mod-stream-debuginfoUpgrade nginx-debuginfoUpgrade nginx-mod-http-perlUpgrade nginx-mod-http-image-filterUpgrade nginx-mod-mail-debuginfoUpgrade nginx-mod-streamUpgrade nginx-debugsourceUpgrade nginx-filesystemUpgrade nginx-mod-mailUpgrade nginx-mod-http-perl-debuginfoUpgrade nginx-all-modulesNo solution existsUpgrade nginxUpgrade nginx-mod-http-xslt-filter-debuginfo | Dec 21, 2020 | Jan 9, 2020 |
| Suse | — | Upgrade vim-plugin-nginxUpgrade nginxUpgrade nginx-source | Feb 12, 2020 | Jan 9, 2020 |
| Ubuntu | — | Upgrade nginx-core (Ubuntu Pro)Upgrade nginx-light (Ubuntu Pro)Upgrade nginx-coreUpgrade nginx-lightUpgrade nginx-extras (Ubuntu Pro)Upgrade nginx-commonUpgrade nginx-common (Ubuntu Pro)Upgrade nginx-extrasUpgrade nginx-fullUpgrade nginx-full (Ubuntu Pro) | Jan 14, 2020 | Jan 9, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jan 9, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub