PT-2024-1653 · Nginx+1 · Nginx Plus+3

Published

2024-02-02

·

Updated

2025-01-24

·

CVE-2024-24990

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
The affected software includes NGINX Plus and NGINX OSS, specifically when configured to use the HTTP/3 QUIC module. This issue may allow a remote attacker to cause a denial of service due to undisclosed requests that can cause worker processes to terminate. The HTTP/3 QUIC module is not enabled by default and is considered experimental. An exploit is available, but details are not provided here. The issue is related to the use of memory after it has been freed, which can be exploited by a remote attacker to cause a denial of service. For more information, refer to Support for QUIC and HTTP/3 https://nginx.org/en/docs/quic.html . Vulnerable versions are not specified, but software versions which have reached End of Technical Support (EoTS) are not evaluated. #NGINX #NGINXPlus #HTTP3 #QUIC #cybersecurity #infosec #nginxoss #denialofservice

Fix

Use After Free

Weakness Enumeration

Related Identifiers

BDU:2024-01328
BIT-NGINX-2024-24990
BIT-NGINX-GATEWAY-2024-24990
CVE-2024-24990

Affected Products

Nginx Oss
Nginx Plus
Nginx
Red Os