When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 encoder instructions can cause NGINX worker processes to terminate or cause or other potential impact.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-nginx | Aug 22, 2024 | May 29, 2024 | |
| Freebsd | freebsd-upgrade-package-nginx-develfreebsd-upgrade-package-nginx | May 30, 2024 | May 29, 2024 | |
| Nginx | nginx-nginx-upgrade-1_26_1nginx-nginx-upgrade-1_27_0 | May 30, 2024 | May 30, 2024 | |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Jan 20, 2025 | May 29, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub