PT-2020-6649 · Nginx+6 · Nginx+6

Bert Jw Regeer

+1

·

Published

2020-01-09

·

Updated

2026-04-21

·

CVE-2019-20372

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions NGINX versions prior to 1.17.7
Description The issue is related to HTTP request smuggling in NGINX, which can be exploited by an attacker to read unauthorized web pages, particularly in environments where NGINX is fronted by a load balancer. This is due to insufficient handling of HTTP requests. The vulnerability can allow a remote attacker to gain unauthorized access to information.
Recommendations For NGINX versions prior to 1.17.7, update to version 1.17.7 or later to resolve the issue. For versions prior to 1.21.0, updating to version 1.21.0 can also address multiple related issues, including this one.

Exploit

Fix

HTTP Request/Response Smuggling

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2636
ALT-PU-2020-2686
BDU:2022-02389
CESA-2020_5495
CLEANSTART-2026-AF45008
CLEANSTART-2026-BA37192
CLEANSTART-2026-MQ02912
CLEANSTART-2026-XB16901
CLEANSTART-2026-ZN32454
CLEANSTART-2026-ZT77083
CVE-2019-20372
ELSA-2020-5495
MGASA-2020-0231
OPENSUSE-SU-2020:0204-1
OPENSUSE-SU-2020_0204-1
OPENSUSE-SU-2024:11092-1
RHSA-2020:2817
RHSA-2020:5495
RHSA-2020_5495
SUSE-SU-2020:0348-1
SUSE-SU-2020:1171-1
SUSE-SU-2020_0348-1
SUSE-SU-2020_1171-1
USN-4235-1
USN-4235-2

Affected Products

Alt Linux
Centos
Apple Macos
Nginx
Red Hat
Suse
Ubuntu