cbcvebase.
CVE-2020-36309
published 2021-04-06

CVE-2020-36309: ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows unsafe characters in an argument when using the API to mutate a URI, or a request…

medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows unsafe characters in an argument when using the API to mutate a URI, or a request or response header.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlibnginx-mod-http-lua< nginx 1.22.0-3 (bookworm)nginx 1.22.0-3 (bookworm)
debiannginx< nginx 1.22.0-3 (bookworm)nginx 1.22.0-3 (bookworm)
f5nginx>= 0 < 1.18.0-6.1+deb11u51.18.0-6.1+deb11u5
f5nginx>= 0 < 1.22.0-31.22.0-3
f5nginx>= 0 < 1.22.0-31.22.0-3
f5nginx>= 0 < 1.22.0-31.22.0-3
f5nginx>= 0 < 1.14.0-0ubuntu1.101.14.0-0ubuntu1.10
f5nginx>= 0 < 1.18.0-0ubuntu1.31.18.0-0ubuntu1.3
f5nginx>= 0 < 1.18.0-6ubuntu14.11.18.0-6ubuntu14.1
f5nginx>= 0 < 1.10.3-0ubuntu0.16.04.5+esm31.10.3-0ubuntu0.16.04.5+esm3
f5nginx>= 0 < 1.10.3-0ubuntu0.16.04.5+esm41.10.3-0ubuntu0.16.04.5+esm4
openrestylua-nginx-module< 0.10.160.10.16

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
osv7.5HIGH