CVE-2013-4547
published 2013-11-23CVE-2013-4547: nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescaped space character in a URI.
PriorityP268high7.5CVSS 2.0
AVNACLAuNCPIPAP
EXPLOIT
EPSS
67.72%
99.2th percentile
nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescaped space character in a URI.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nginx | < nginx 1.4.4-1 (bookworm) | nginx 1.4.4-1 (bookworm) |
| f5 | nginx | >= 0 < 1.4.4-1 | 1.4.4-1 |
| f5 | nginx | >= 0 < 1.4.4-1 | 1.4.4-1 |
| f5 | nginx | >= 0 < 1.4.4-1 | 1.4.4-1 |
| f5 | nginx | >= 0 < 1.4.4-1 | 1.4.4-1 |
| f5 | nginx | >= 0.8.41 < 1.4.4 | 1.4.4 |
| f5 | nginx | 1.5.0 – 1.5.6 | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| suse | lifecycle_management_server | — | — |
| suse | studio_onsite | — | — |
| suse | webyast | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect HTTP requests containing an unescaped space character in the URI — the core indicator of CVE-2013-4547 exploitation attempts against nginx. ↗
- →Use the nginx workaround rule as a detection/blocking signature: flag or block any request whose $request_uri contains a literal space character. ↗
- →The exploit payload pattern is a filename followed by a space and a null byte then a script extension (e.g. '/file \0.php'), used to confuse nginx's URI parser into treating a static file as a PHP script. ↗
- ·Vulnerability only affects nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7; fixed in 1.4.4 and 1.5.7. ↗
- ·The bypass is rooted in how nginx's HTTP request parser handles URIs with unescaped space characters; configurations using location blocks with script handlers (e.g. PHP-FPM) are most at risk. ↗
- ·An official patch for older/unsupported versions is available at http://nginx.org/download/patch.2013.space.txt ↗
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2013-4547: nginx - nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to byp...
vendor_debian·2013·CVSS 7.5
CVE-2013-4547 [HIGH] CVE-2013-4547: nginx - nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to byp...
nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescaped space character in a URI.
Scope: local
bookworm: resolved (fixed in 1.4.4-1)
bullseye: resolved (fixed in 1.4.4-1)
forky: resolved (fixed in 1.4.4-1)
sid: resolved (fixed in 1.4.4-1)
trixie: resolved (fixed in 1.4.4-1)
GHSA
GHSA-9x2q-qf8w-h347: nginx 0
ghsa_unreviewed·2022-05-13
CVE-2013-4547 [HIGH] CWE-116 GHSA-9x2q-qf8w-h347: nginx 0
nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescaped space character in a URI.
OSV
CVE-2013-4547: nginx 0
osv·2013-11-23·CVSS 7.5
CVE-2013-4547 [HIGH] CVE-2013-4547: nginx 0
nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescaped space character in a URI.
No detection rules found.
Bugzilla
CVE-2013-4547 nginx: security restriction bypass flaw due to whitespace parsing [fedora-all]
bugzilla·2013-11-19·CVSS 7.5
CVE-2013-4547 [HIGH] CVE-2013-4547 nginx: security restriction bypass flaw due to whitespace parsing [fedora-all]
CVE-2013-4547 nginx: security restriction bypass flaw due to whitespace parsing [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note:
Bugzilla
CVE-2013-4547 nginx: security restriction bypass flaw due to whitespace parsing [epel-6]
bugzilla·2013-11-19·CVSS 7.5
CVE-2013-4547 [HIGH] CVE-2013-4547 nginx: security restriction bypass flaw due to whitespace parsing [epel-6]
CVE-2013-4547 nginx: security restriction bypass flaw due to whitespace parsing [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-6 trac
Bugzilla
CVE-2013-4547 nginx: security restriction bypass flaw due to whitespace parsing
bugzilla·2013-11-19·CVSS 7.5
CVE-2013-4547 [HIGH] CVE-2013-4547 nginx: security restriction bypass flaw due to whitespace parsing
CVE-2013-4547 nginx: security restriction bypass flaw due to whitespace parsing
It was reported [1] that nginx suffered from a flaw where an attacker could bypass security restrictions in certain configurations due to how the HTTP request parser handled URI's with an unescaped space character.
This problem affects nginx 0.8.41 through to 1.5.6; new 1.5.7 and 1.4.4 releases are available to correct this. A patch [2] also exists for older versions.
As a temporary workaround the following configuration can be used in each server{} block:
if ($request_uri ~ " ") {
return 444;
}
[1] http://mailman.nginx.org/pipermail/nginx-announce/2013/000125.html
[2] http://nginx.org/download/patch.2013.space.txt
Discussion:
Created nginx tracking bugs for this issue:
Affects: fedora-all [bug 1032267]
Bugzilla
CVE-2013-4547 nginx: security restriction bypass flaw due to whitespace parsing [epel-5]
bugzilla·2013-11-19·CVSS 7.5
CVE-2013-4547 [HIGH] CVE-2013-4547 nginx: security restriction bypass flaw due to whitespace parsing [epel-5]
CVE-2013-4547 nginx: security restriction bypass flaw due to whitespace parsing [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-5 trac
http://lists.opensuse.org/opensuse-security-announce/2013-12/msg00007.htmlhttp://lists.opensuse.org/opensuse-updates/2013-11/msg00084.htmlhttp://lists.opensuse.org/opensuse-updates/2013-11/msg00118.htmlhttp://lists.opensuse.org/opensuse-updates/2013-11/msg00119.htmlhttp://mailman.nginx.org/pipermail/nginx-announce/2013/000125.htmlhttp://secunia.com/advisories/55757http://secunia.com/advisories/55822http://secunia.com/advisories/55825http://www.debian.org/security/2012/dsa-2802http://lists.opensuse.org/opensuse-security-announce/2013-12/msg00007.htmlhttp://lists.opensuse.org/opensuse-updates/2013-11/msg00084.htmlhttp://lists.opensuse.org/opensuse-updates/2013-11/msg00118.htmlhttp://lists.opensuse.org/opensuse-updates/2013-11/msg00119.htmlhttp://mailman.nginx.org/pipermail/nginx-announce/2013/000125.htmlhttp://secunia.com/advisories/55757http://secunia.com/advisories/55822http://secunia.com/advisories/55825http://www.debian.org/security/2012/dsa-2802
2013-11-23
Published