CVE-2019-20372
MEDIUM | Platform: Xcode | Changelog
CVE Details
Description
NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.
CVSS 3.1 Score
| Metric | Value |
|---|---|
| Base Score | 5.3 (MEDIUM) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Weakness
References
- Apple Security Advisory
- NVD Entry
- http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00013.html (Mailing List, Third Party Advisory)
- http://nginx.org/en/CHANGES (Mitigation, Release Notes, Vendor Advisory)
- http://seclists.org/fulldisclosure/2021/Sep/36 (Mailing List, Third Party Advisory)
- https://bertjwregeer.keybase.pub/2019-12-10%20-%20error_page%20request%20smuggling.pdf (Exploit, Mitigation, Third Party Advisory)
- https://duo.com/docs/dng-notes#version-1.5.4-january-2020 (Release Notes, Third Party Advisory)
- https://github.com/kubernetes/ingress-nginx/pull/4859 (Patch, Third Party Advisory)
- https://github.com/nginx/nginx/commit/c1be55f97211d38b69ac0c2027e6812ab8b1b94e (Patch, Vendor Advisory)
- https://security.netapp.com/advisory/ntap-20200127-0003/ (Third Party Advisory)