QID 730432
Date Published: 2022-04-11
QID 730432: Nginx Remote Code Execution (RCE) Vulnerability (Zero Day)
nginx [engine x] is an HTTP and reverse proxy server, a mail proxy server, and a generic TCP/UDP proxy server.
An nginx Zero-Day RCE issue was identified in the nginx LDAP-auth daemon implementation.
Affected Versions:
Nginx version 1.18
QID Detection Logic (Unauthenticated):
This unauthenticated check vulnerable version of Nginx by grabbing the version from the server banner of HTTP response.
Note: This QID does not check for LDAP implementation of NGINX and is therefore kept potential
Successful exploitation of the vulnerability may allow arbitrary remote code execution.
Solution
Patch is not available, for more information about this vulnerability please refer to Nginx RCE Vulnerability
Vendor References
- NGINX Security Advisory -
www.nginx.com/blog/addressing-security-weaknesses-nginx-ldap-reference-implementation/
CVEs related to QID 730432
Software Advisories
| Advisory ID | Software | Component | Link |
|---|