An issue was discovered in OpenResty before 1.15.8.4. ngx_http_lua_subrequest.c allows HTTP request smuggling, as demonstrated by the ngx.location.capture API.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade nginx | Jul 23, 2020 | Apr 12, 2020 |
| Ubuntu | — | Upgrade nginx-coreUpgrade nginx-extras (Ubuntu Pro)Upgrade nginx-lightUpgrade libnginx-mod-http-luaUpgrade nginx-core (Ubuntu Pro)Upgrade nginx-full (Ubuntu Pro)Upgrade nginx-fullUpgrade nginx-extrasUpgrade nginx-light (Ubuntu Pro) | Apr 13, 2022 | Apr 12, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub