Lucene search

K
ubuntucveUbuntu.comUB:CVE-2020-11724
HistoryApr 12, 2020 - 12:00 a.m.

CVE-2020-11724

2020-04-1200:00:00
ubuntu.com
ubuntu.com
23

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS

0.004

Percentile

74.2%

An issue was discovered in OpenResty before 1.15.8.4.
ngx_http_lua_subrequest.c allows HTTP request smuggling, as demonstrated by
the ngx.location.capture API.

Bugs

Notes

Author Note
mdeslaur The lua module is included in the debian directory as it is not part of the upstream nginx release. It is included in the nginx-extras binary package in universe.
OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchnginx< 1.14.0-0ubuntu1.10UNKNOWN
ubuntu20.04noarchnginx< 1.18.0-0ubuntu1.3UNKNOWN
ubuntu14.04noarchnginx< anyUNKNOWN
ubuntu16.04noarchnginx< 1.10.3-0ubuntu0.16.04.5+esm4UNKNOWN

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS

0.004

Percentile

74.2%