PT-2020-6649 · Nginx+6 · Nginx+6
Bert Jw Regeer
+1
·
Published
2020-01-09
·
Updated
2026-04-21
·
CVE-2019-20372
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
NGINX versions prior to 1.17.7
Description
The issue is related to HTTP request smuggling in NGINX, which can be exploited by an attacker to read unauthorized web pages, particularly in environments where NGINX is fronted by a load balancer. This is due to insufficient handling of HTTP requests. The vulnerability can allow a remote attacker to gain unauthorized access to information.
Recommendations
For NGINX versions prior to 1.17.7, update to version 1.17.7 or later to resolve the issue.
For versions prior to 1.21.0, updating to version 1.21.0 can also address multiple related issues, including this one.
Exploit
Fix
HTTP Request/Response Smuggling
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Centos
Apple Macos
Nginx
Red Hat
Suse
Ubuntu