Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Algtm

#24805de 53,635
9.8CVSS total
Vulnerabilidades · 1
PT-2018-15227
9.8
2018-12-10
Nginx · Verynginx · CVE-2018-19991
**Name of the Vulnerable Software and Affected Versions** VeryNginx version 0.3.3 **Description** The issue allows remote attackers to bypass the Web Application Firewall feature due to the lack of an error handler for functions such as `get uri args` or `get post args`, which can lead to API misuse. **Recommendations** For VeryNginx version 0.3.3, consider implementing a custom error handler to block potential API misuse until a patch is available. As a temporary workaround, review and restrict access to sensitive API endpoints to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.