CVE-2011-4968

Severity
4.8MEDIUM
EPSS
0.4%
top 39.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 19
Latest updateApr 22

Description

nginx http proxy module does not verify peer identity of https origin server which could facilitate man-in-the-middle attack (MITM)

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:NExploitability: 2.2 | Impact: 2.5

Affected Packages3 packages

Debiannginx< 1.9.1-1+3
NVDf5/nginx10 versions+9
CVEListV5nginx/nginxthrough 1.6.2

Also affects: Debian Linux 8.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-x9wg-g9hq-p992: nginx http proxy module does not verify peer identity of https origin server which could facilitate man-in-the-middle attack (MITM)2022-04-22
CVEList
CVE-2011-4968: nginx http proxy module does not verify peer identity of https origin server which could facilitate man-in-the-middle attack (MITM)2019-11-19
OSV
CVE-2011-4968: nginx http proxy module does not verify peer identity of https origin server which could facilitate man-in-the-middle attack (MITM)2019-11-19

📋Vendor Advisories

1
Debian
CVE-2011-4968: nginx - nginx http proxy module does not verify peer identity of https origin server whi...2011

💬Community

3
Bugzilla
CVE-2011-4968 nginx: http proxy module does not validate SSL certificates2013-01-04
Bugzilla
CVE-2011-4968 nginx: http proxy module does not validate SSL certificates [epel-all]2013-01-04
Bugzilla
CVE-2011-4968 nginx: http proxy module does not validate SSL certificates [fedora-all]2013-01-04