CVE-2011-4968
Severity
4.8MEDIUM
EPSS
0.4%
top 39.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 19
Latest updateApr 22
Description
nginx http proxy module does not verify peer identity of https origin server which could facilitate man-in-the-middle attack (MITM)
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:NExploitability: 2.2 | Impact: 2.5
Affected Packages3 packages
Also affects: Debian Linux 8.0
Patches
🔴Vulnerability Details
3GHSA▶
GHSA-x9wg-g9hq-p992: nginx http proxy module does not verify peer identity of https origin server which could facilitate man-in-the-middle attack (MITM)↗2022-04-22
CVEList▶
CVE-2011-4968: nginx http proxy module does not verify peer identity of https origin server which could facilitate man-in-the-middle attack (MITM)↗2019-11-19
OSV▶
CVE-2011-4968: nginx http proxy module does not verify peer identity of https origin server which could facilitate man-in-the-middle attack (MITM)↗2019-11-19
📋Vendor Advisories
1Debian▶
CVE-2011-4968: nginx - nginx http proxy module does not verify peer identity of https origin server whi...↗2011
💬Community
3Bugzilla
▶
Bugzilla
▶