QID 198741

Date Published: 2022-04-14

QID 198741: Ubuntu Security Notification for nginx Vulnerabilities (USN-5371-1)

Nginx lua module mishandled certain inputs.
Nginx lua module mishandled certain inputs.
Nginx mishandled the use ofcompatible certificates among multiple encryption protocols.

An attacker could possibly use this issue to perform an http requestsmuggling attack.
An attacker could possibly use this issue to disclose sensitiveinformation.
If a remote attacker were able to intercept the communication,this issue could be used to redirect traffic between subdomains.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution
    Refer to Ubuntu security advisory USN-5371-1 for updates and patch information.
    Vendor References

    CVEs related to QID 198741

    Software Advisories
    Advisory ID Software Component Link
    USN-5371-1 Ubuntu Linux URL Logo ubuntu.com/security/notices/USN-5371-1