PT-2024-1653 · Nginx+1 · Nginx Plus+3
Published
2024-02-02
·
Updated
2025-01-24
·
CVE-2024-24990
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
The affected software includes NGINX Plus and NGINX OSS, specifically when configured to use the HTTP/3 QUIC module.
This issue may allow a remote attacker to cause a denial of service due to undisclosed requests that can cause worker processes to terminate.
The HTTP/3 QUIC module is not enabled by default and is considered experimental.
An exploit is available, but details are not provided here.
The issue is related to the use of memory after it has been freed, which can be exploited by a remote attacker to cause a denial of service.
For more information, refer to Support for QUIC and HTTP/3 https://nginx.org/en/docs/quic.html .
Vulnerable versions are not specified, but software versions which have reached End of Technical Support (EoTS) are not evaluated.
#NGINX #NGINXPlus #HTTP3 #QUIC #cybersecurity #infosec #nginxoss #denialofservice
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nginx Oss
Nginx Plus
Nginx
Red Os