NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
History
No history.
Information
Published : 2020-01-09 21:15
Updated : 2024-11-21 04:38
NVD link : CVE-2019-20372
Mitre link : CVE-2019-20372
CVE.ORG link : CVE-2019-20372
JSON object : View
Products Affected
canonical
- ubuntu_linux
netapp
- cloud_backup
f5
- nginx
opensuse
- leap
apple
- xcode
CWE
CWE-444
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')