Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2021-23017

CWE-19316 documents12 sources
Severity
7.7HIGH
EPSS
73.5%
top 1.20%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJun 1
Latest updateApr 15

Description

A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:LExploitability: 2.2 | Impact: 5.5

Affected Packages12 packages

NVDf5/nginx0.6.181.20.1
Debiannginx< 1.18.0-6.1+3
NVDoracle/goldengate< 21.4.0.0.0
NVDopenresty/openresty< 1.19.3.2

Also affects: Fedora 33, 34

Patches

🔴Vulnerability Details

3
GHSA
GHSA-83p9-mcpm-374v: A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte2022-05-24
OSV
CVE-2021-23017: A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte2021-06-01
CVEList
CVE-2021-23017: A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte2021-06-01

💥Exploits & PoCs

1
Exploit-DB
Nginx 1.20.0 - Denial of Service (DOS)2022-07-11

📋Vendor Advisories

10
Oracle
Oracle Oracle Blockchain Platform Risk Matrix: BCS Console (nginx) — CVE-2021-230172023-04-15
Oracle
Oracle Oracle Blockchain Platform Risk Matrix: Backend (nginx) — CVE-2021-230172022-04-15
Oracle
Oracle Oracle GoldenGate Risk Matrix: GG Market Place for Support (nginx) — CVE-2021-230172022-01-15
Oracle
Oracle Oracle Communications Risk Matrix: Infrastructure (nginx) — CVE-2021-230172021-10-15
Microsoft
A security issue in nginx resolver was identified which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite resulting in worker process crash 2021-06-08

💬Community

1
HackerOne
1-byte heap buffer overflow in DNS resolver2021-08-27