Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:30738
HistoryMay 28, 2021 - 1:25 p.m.

Remote Code Execution

2021-05-2813:25:37
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
1651
nginx
remote code execution
vulnerability
off-by-one error
dns responses

EPSS

0.316

Percentile

97.1%

nginx is vulnerable to remote code execution. A remote attacker who is able to provide DNS responses to a nginx server can likely achieve remote code execution due to an off-by-one error in ngx_resolver_copy() while processing DNS responses.

References