cbcvebase.
CVE-2020-11724
published 2020-04-12

CVE-2020-11724: An issue was discovered in OpenResty before 1.15.8.4. ngx_http_lua_subrequest.c allows HTTP request smuggling, as demonstrated by the ngx.location.capture API.

high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
An issue was discovered in OpenResty before 1.15.8.4. ngx_http_lua_subrequest.c allows HTTP request smuggling, as demonstrated by the ngx.location.capture API.

Affected

13 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiannginx< nginx 1.18.0-5 (bookworm)nginx 1.18.0-5 (bookworm)
f5nginx>= 0 < 1.18.0-51.18.0-5
f5nginx>= 0 < 1.18.0-51.18.0-5
f5nginx>= 0 < 1.18.0-51.18.0-5
f5nginx>= 0 < 1.18.0-51.18.0-5
f5nginx>= 0 < 1.14.0-0ubuntu1.101.14.0-0ubuntu1.10
f5nginx>= 0 < 1.18.0-0ubuntu1.31.18.0-0ubuntu1.3
f5nginx>= 0 < 1.18.0-6ubuntu14.11.18.0-6ubuntu14.1
f5nginx>= 0 < 1.10.3-0ubuntu0.16.04.5+esm31.10.3-0ubuntu0.16.04.5+esm3
f5nginx>= 0 < 1.10.3-0ubuntu0.16.04.5+esm41.10.3-0ubuntu0.16.04.5+esm4
openrestyopenresty< 1.15.8.41.15.8.4

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
osv7.5HIGH