CVE-2020-11724
published 2020-04-12CVE-2020-11724: An issue was discovered in OpenResty before 1.15.8.4. ngx_http_lua_subrequest.c allows HTTP request smuggling, as demonstrated by the ngx.location.capture API.
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
2.60%
83.7th percentile
An issue was discovered in OpenResty before 1.15.8.4. ngx_http_lua_subrequest.c allows HTTP request smuggling, as demonstrated by the ngx.location.capture API.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | nginx | < nginx 1.18.0-5 (bookworm) | nginx 1.18.0-5 (bookworm) |
| f5 | nginx | >= 0 < 1.18.0-5 | 1.18.0-5 |
| f5 | nginx | >= 0 < 1.18.0-5 | 1.18.0-5 |
| f5 | nginx | >= 0 < 1.18.0-5 | 1.18.0-5 |
| f5 | nginx | >= 0 < 1.18.0-5 | 1.18.0-5 |
| f5 | nginx | >= 0 < 1.14.0-0ubuntu1.10 | 1.14.0-0ubuntu1.10 |
| f5 | nginx | >= 0 < 1.18.0-0ubuntu1.3 | 1.18.0-0ubuntu1.3 |
| f5 | nginx | >= 0 < 1.18.0-6ubuntu14.1 | 1.18.0-6ubuntu14.1 |
| f5 | nginx | >= 0 < 1.10.3-0ubuntu0.16.04.5+esm3 | 1.10.3-0ubuntu0.16.04.5+esm3 |
| f5 | nginx | >= 0 < 1.10.3-0ubuntu0.16.04.5+esm4 | 1.10.3-0ubuntu0.16.04.5+esm4 |
| openresty | openresty | < 1.15.8.4 | 1.15.8.4 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
nginx vulnerability
vendor_ubuntu·2022-10-07·CVSS 7.5
CVE-2020-11724 [HIGH] nginx vulnerability
Title: nginx vulnerability
Summary: A security issue was fixed in nginx's lua module.
USN-5371-1 and USN-5371-2 fixed several vulnerabilities in nginx.
This update provides the corresponding update for CVE-2020-11724
for Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that nginx Lua module mishandled certain inputs.
An attacker could possibly use this issue to perform an HTTP Request
Smuggling attack. This issue was fixed for Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-11724)
It was discovered that nginx Lua module mishandled certain inputs.
An attacker could possibly use this issue to disclose sensitive
information. This issue only affects Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-36309)
It was discovered that nginx mishandled the use of
compatible certifi
Ubuntu
nginx vulnerability
vendor_ubuntu·2022-04-28·CVSS 7.5
CVE-2021-3618 [HIGH] nginx vulnerability
Title: nginx vulnerability
Summary: nginx could be made to redirect network traffic.
USN-5371-1 fixed several vulnerabilities in nginx.
This update provides the fix for CVE-2021-3618 for Ubuntu 22.04 LTS.
Original advisory details:
It was discovered that nginx Lua module mishandled certain inputs.
An attacker could possibly use this issue to perform an HTTP Request
Smuggling attack. This issue was fixed for Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-11724)
It was discovered that nginx Lua module mishandled certain inputs.
An attacker could possibly use this issue to disclose sensitive
information. This issue only affects Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-36309)
It was discovered that nginx mishandled the use of
compatible certificates among multiple encryption pr
Ubuntu
nginx vulnerabilities
vendor_ubuntu·2022-04-12·CVSS 7.5
CVE-2020-36309 [HIGH] nginx vulnerabilities
Title: nginx vulnerabilities
Summary: Several security issues were fixed in nginx.
It was discovered that nginx Lua module mishandled certain inputs.
An attacker could possibly use this issue to perform an HTTP Request
Smuggling attack. This issue was fixed for Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-11724)
It was discovered that nginx Lua module mishandled certain inputs.
An attacker could possibly use this issue to disclose sensitive
information. This issue only affects Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-36309)
It was discovered that nginx mishandled the use of
compatible certificates among multiple encryption protocols.
If a remote attacker were able to intercept the communication,
this issue could be used to redirect traffic between subdomains.
(CVE-2021-3618
Debian
CVE-2020-11724: nginx - An issue was discovered in OpenResty before 1.15.8.4. ngx_http_lua_subrequest.c ...
vendor_debian·2020·CVSS 7.5
CVE-2020-11724 [HIGH] CVE-2020-11724: nginx - An issue was discovered in OpenResty before 1.15.8.4. ngx_http_lua_subrequest.c ...
An issue was discovered in OpenResty before 1.15.8.4. ngx_http_lua_subrequest.c allows HTTP request smuggling, as demonstrated by the ngx.location.capture API.
Scope: local
bookworm: resolved (fixed in 1.18.0-5)
bullseye: resolved (fixed in 1.18.0-5)
forky: resolved (fixed in 1.18.0-5)
sid: resolved (fixed in 1.18.0-5)
trixie: resolved (fixed in 1.18.0-5)
OSV
nginx vulnerability
osv·2022-10-07·CVSS 7.5
CVE-2020-11724 [HIGH] nginx vulnerability
nginx vulnerability
USN-5371-1 and USN-5371-2 fixed several vulnerabilities in nginx.
This update provides the corresponding update for CVE-2020-11724
for Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that nginx Lua module mishandled certain inputs.
An attacker could possibly use this issue to perform an HTTP Request
Smuggling attack. This issue was fixed for Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-11724)
It was discovered that nginx Lua module mishandled certain inputs.
An attacker could possibly use this issue to disclose sensitive
information. This issue only affects Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-36309)
It was discovered that nginx mishandled the use of
compatible certificates among multiple encryption protocols.
If a remote attacker wer
GHSA
GHSA-478m-xrv3-7r93: An issue was discovered in OpenResty before 1
ghsa_unreviewed·2022-05-24
CVE-2020-11724 [HIGH] CWE-444 GHSA-478m-xrv3-7r93: An issue was discovered in OpenResty before 1
An issue was discovered in OpenResty before 1.15.8.4. ngx_http_lua_subrequest.c allows HTTP request smuggling, as demonstrated by the ngx.location.capture API.
OSV
nginx vulnerability
osv·2022-04-28·CVSS 7.5
CVE-2021-3618 [HIGH] nginx vulnerability
nginx vulnerability
USN-5371-1 fixed several vulnerabilities in nginx.
This update provides the fix for CVE-2021-3618 for Ubuntu 22.04 LTS.
Original advisory details:
It was discovered that nginx Lua module mishandled certain inputs.
An attacker could possibly use this issue to perform an HTTP Request
Smuggling attack. This issue was fixed for Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-11724)
It was discovered that nginx Lua module mishandled certain inputs.
An attacker could possibly use this issue to disclose sensitive
information. This issue only affects Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-36309)
It was discovered that nginx mishandled the use of
compatible certificates among multiple encryption protocols.
If a remote attacker were able to intercept the communica
OSV
nginx vulnerabilities
osv·2022-04-12·CVSS 7.5
CVE-2020-11724 [HIGH] nginx vulnerabilities
nginx vulnerabilities
It was discovered that nginx Lua module mishandled certain inputs.
An attacker could possibly use this issue to perform an HTTP Request
Smuggling attack. This issue was fixed for Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-11724)
It was discovered that nginx Lua module mishandled certain inputs.
An attacker could possibly use this issue to disclose sensitive
information. This issue only affects Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-36309)
It was discovered that nginx mishandled the use of
compatible certificates among multiple encryption protocols.
If a remote attacker were able to intercept the communication,
this issue could be used to redirect traffic between subdomains.
(CVE-2021-3618)
OSV
CVE-2020-11724: An issue was discovered in OpenResty before 1
osv·2020-04-12·CVSS 7.5
CVE-2020-11724 [HIGH] CVE-2020-11724: An issue was discovered in OpenResty before 1
An issue was discovered in OpenResty before 1.15.8.4. ngx_http_lua_subrequest.c allows HTTP request smuggling, as demonstrated by the ngx.location.capture API.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/openresty/lua-nginx-module/commit/9ab38e8ee35fc08a57636b1b6190dca70b0076fahttps://github.com/openresty/openresty/blob/4e8b4c395f842a078e429c80dd063b2323999957/patches/ngx_http_lua-0.10.15-fix_location_capture_content_length_chunked.patchhttps://lists.debian.org/debian-lts-announce/2020/07/msg00014.htmlhttps://security.netapp.com/advisory/ntap-20210129-0002/https://www.debian.org/security/2020/dsa-4750https://github.com/openresty/lua-nginx-module/commit/9ab38e8ee35fc08a57636b1b6190dca70b0076fahttps://github.com/openresty/openresty/blob/4e8b4c395f842a078e429c80dd063b2323999957/patches/ngx_http_lua-0.10.15-fix_location_capture_content_length_chunked.patchhttps://lists.debian.org/debian-lts-announce/2020/07/msg00014.htmlhttps://security.netapp.com/advisory/ntap-20210129-0002/https://www.debian.org/security/2020/dsa-4750
2020-04-12
Published