An issue was discovered in OpenResty before 1.15.8.4. ngx_http_lua_subrequest.c allows HTTP request smuggling, as demonstrated by the ngx.location.capture API.
References
Configurations
History
No history.
Information
Published : 2020-04-12 21:15
Updated : 2024-11-21 04:58
NVD link : CVE-2020-11724
Mitre link : CVE-2020-11724
CVE.ORG link : CVE-2020-11724
JSON object : View
Products Affected
debian
- debian_linux
openresty
- openresty
CWE
CWE-444
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')