QID 198766

Date Published: 2022-05-05

QID 198766: Ubuntu Security Notification for nginx Vulnerability (USN-5371-2)

Nginx lua module mishandled certain inputs.
Nginx lua module mishandled certain inputs.
Nginx mishandled the use of compatible certificates among multiple encryption protocols.

Usn-5371-1 fixed several vulnerabilities in nginx.
This update provides the fix for cve-2021-3618 for ubuntu 22.
An attacker could possibly use this issue to perform an http request smuggling attack.
An attacker could possibly use this issue to disclose sensitive information.
If a remote attacker were able to intercept the communication, this issue could be used to redirect traffic between subdomains.

  • CVSS V3 rated as High - 7.4 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution
    Refer to Ubuntu security advisory USN-5371-2 for updates and patch information.
    Vendor References

    CVEs related to QID 198766

    Software Advisories
    Advisory ID Software Component Link
    USN-5371-2 Ubuntu Linux URL Logo ubuntu.com/security/notices/USN-5371-2