CVE-2020-36309
published 2021-04-06CVE-2020-36309: ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows unsafe characters in an argument when using the API to mutate a URI, or a request…
PriorityP429medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
1.31%
67.5th percentile
ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows unsafe characters in an argument when using the API to mutate a URI, or a request or response header.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libnginx-mod-http-lua | < nginx 1.22.0-3 (bookworm) | nginx 1.22.0-3 (bookworm) |
| debian | nginx | < nginx 1.22.0-3 (bookworm) | nginx 1.22.0-3 (bookworm) |
| f5 | nginx | >= 0 < 1.18.0-6.1+deb11u5 | 1.18.0-6.1+deb11u5 |
| f5 | nginx | >= 0 < 1.22.0-3 | 1.22.0-3 |
| f5 | nginx | >= 0 < 1.22.0-3 | 1.22.0-3 |
| f5 | nginx | >= 0 < 1.22.0-3 | 1.22.0-3 |
| f5 | nginx | >= 0 < 1.14.0-0ubuntu1.10 | 1.14.0-0ubuntu1.10 |
| f5 | nginx | >= 0 < 1.18.0-0ubuntu1.3 | 1.18.0-0ubuntu1.3 |
| f5 | nginx | >= 0 < 1.18.0-6ubuntu14.1 | 1.18.0-6ubuntu14.1 |
| f5 | nginx | >= 0 < 1.10.3-0ubuntu0.16.04.5+esm3 | 1.10.3-0ubuntu0.16.04.5+esm3 |
| f5 | nginx | >= 0 < 1.10.3-0ubuntu0.16.04.5+esm4 | 1.10.3-0ubuntu0.16.04.5+esm4 |
| openresty | lua-nginx-module | < 0.10.16 | 0.10.16 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
nginx vulnerability
osv·2022-10-07·CVSS 7.5
CVE-2020-11724 [HIGH] nginx vulnerability
nginx vulnerability
USN-5371-1 and USN-5371-2 fixed several vulnerabilities in nginx.
This update provides the corresponding update for CVE-2020-11724
for Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that nginx Lua module mishandled certain inputs.
An attacker could possibly use this issue to perform an HTTP Request
Smuggling attack. This issue was fixed for Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-11724)
It was discovered that nginx Lua module mishandled certain inputs.
An attacker could possibly use this issue to disclose sensitive
information. This issue only affects Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-36309)
It was discovered that nginx mishandled the use of
compatible certificates among multiple encryption protocols.
If a remote attacker wer
GHSA
GHSA-j8m6-95xp-pmp6: ngx_http_lua_module (aka lua-nginx-module) before 0
ghsa_unreviewed·2022-05-24
CVE-2020-36309 [MEDIUM] GHSA-j8m6-95xp-pmp6: ngx_http_lua_module (aka lua-nginx-module) before 0
ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows unsafe characters in an argument when using the API to mutate a URI, or a request or response header.
OSV
nginx vulnerability
osv·2022-04-28·CVSS 7.5
CVE-2021-3618 [HIGH] nginx vulnerability
nginx vulnerability
USN-5371-1 fixed several vulnerabilities in nginx.
This update provides the fix for CVE-2021-3618 for Ubuntu 22.04 LTS.
Original advisory details:
It was discovered that nginx Lua module mishandled certain inputs.
An attacker could possibly use this issue to perform an HTTP Request
Smuggling attack. This issue was fixed for Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-11724)
It was discovered that nginx Lua module mishandled certain inputs.
An attacker could possibly use this issue to disclose sensitive
information. This issue only affects Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-36309)
It was discovered that nginx mishandled the use of
compatible certificates among multiple encryption protocols.
If a remote attacker were able to intercept the communica
OSV
nginx vulnerabilities
osv·2022-04-12·CVSS 7.5
CVE-2020-11724 [HIGH] nginx vulnerabilities
nginx vulnerabilities
It was discovered that nginx Lua module mishandled certain inputs.
An attacker could possibly use this issue to perform an HTTP Request
Smuggling attack. This issue was fixed for Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-11724)
It was discovered that nginx Lua module mishandled certain inputs.
An attacker could possibly use this issue to disclose sensitive
information. This issue only affects Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-36309)
It was discovered that nginx mishandled the use of
compatible certificates among multiple encryption protocols.
If a remote attacker were able to intercept the communication,
this issue could be used to redirect traffic between subdomains.
(CVE-2021-3618)
OSV
CVE-2020-36309: ngx_http_lua_module (aka lua-nginx-module) before 0
osv·2021-04-06·CVSS 5.3
CVE-2020-36309 [MEDIUM] CVE-2020-36309: ngx_http_lua_module (aka lua-nginx-module) before 0
ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows unsafe characters in an argument when using the API to mutate a URI, or a request or response header.
Ubuntu
nginx vulnerability
vendor_ubuntu·2022-10-07·CVSS 7.5
CVE-2020-11724 [HIGH] nginx vulnerability
Title: nginx vulnerability
Summary: A security issue was fixed in nginx's lua module.
USN-5371-1 and USN-5371-2 fixed several vulnerabilities in nginx.
This update provides the corresponding update for CVE-2020-11724
for Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that nginx Lua module mishandled certain inputs.
An attacker could possibly use this issue to perform an HTTP Request
Smuggling attack. This issue was fixed for Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-11724)
It was discovered that nginx Lua module mishandled certain inputs.
An attacker could possibly use this issue to disclose sensitive
information. This issue only affects Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-36309)
It was discovered that nginx mishandled the use of
compatible certifi
Ubuntu
nginx vulnerability
vendor_ubuntu·2022-04-28·CVSS 7.5
CVE-2021-3618 [HIGH] nginx vulnerability
Title: nginx vulnerability
Summary: nginx could be made to redirect network traffic.
USN-5371-1 fixed several vulnerabilities in nginx.
This update provides the fix for CVE-2021-3618 for Ubuntu 22.04 LTS.
Original advisory details:
It was discovered that nginx Lua module mishandled certain inputs.
An attacker could possibly use this issue to perform an HTTP Request
Smuggling attack. This issue was fixed for Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-11724)
It was discovered that nginx Lua module mishandled certain inputs.
An attacker could possibly use this issue to disclose sensitive
information. This issue only affects Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-36309)
It was discovered that nginx mishandled the use of
compatible certificates among multiple encryption pr
Ubuntu
nginx vulnerabilities
vendor_ubuntu·2022-04-12·CVSS 7.5
CVE-2020-36309 [HIGH] nginx vulnerabilities
Title: nginx vulnerabilities
Summary: Several security issues were fixed in nginx.
It was discovered that nginx Lua module mishandled certain inputs.
An attacker could possibly use this issue to perform an HTTP Request
Smuggling attack. This issue was fixed for Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-11724)
It was discovered that nginx Lua module mishandled certain inputs.
An attacker could possibly use this issue to disclose sensitive
information. This issue only affects Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-36309)
It was discovered that nginx mishandled the use of
compatible certificates among multiple encryption protocols.
If a remote attacker were able to intercept the communication,
this issue could be used to redirect traffic between subdomains.
(CVE-2021-3618
Debian
CVE-2020-36309: libnginx-mod-http-lua - ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows un...
vendor_debian·2020·CVSS 5.3
CVE-2020-36309 [MEDIUM] CVE-2020-36309: libnginx-mod-http-lua - ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows un...
ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows unsafe characters in an argument when using the API to mutate a URI, or a request or response header.
Scope: local
bookworm: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/openresty/lua-nginx-module/compare/v0.10.15...v0.10.16https://github.com/openresty/lua-nginx-module/pull/1654https://news.ycombinator.com/item?id=26712562https://security.netapp.com/advisory/ntap-20210507-0005/https://github.com/openresty/lua-nginx-module/compare/v0.10.15...v0.10.16https://github.com/openresty/lua-nginx-module/pull/1654https://lists.debian.org/debian-lts-announce/2025/06/msg00026.htmlhttps://news.ycombinator.com/item?id=26712562https://security.netapp.com/advisory/ntap-20210507-0005/
2021-04-06
Published