PT-2020-3784 · Openresty+2 · Openresty+2

Published

2020-04-12

·

Updated

2022-10-07

·

CVE-2020-11724

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions: OpenResty versions prior to 1.15.8.4
Description: The issue is related to HTTP request smuggling in the ngx http lua subrequest.c component of the OpenResty web server. This is due to inconsistent interpretation of HTTP requests. The vulnerability can be exploited by a remote attacker to impact data integrity. The ngx.location.capture API is affected.
Recommendations: For versions prior to 1.15.8.4, update to version 1.15.8.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the ngx http lua subrequest.c component until a patch is available. Avoid using the ngx.location.capture API in affected versions until the issue is resolved.

Fix

HTTP Request/Response Smuggling

Weakness Enumeration

Related Identifiers

BDU:2020-04146
CVE-2020-11724
DLA-2283-1
DSA-4750-1
USN-5371-1
USN-5371-3

Affected Products

Linuxmint
Openresty
Ubuntu