BDU:2022-02389

Scores

EPSS

0.000none0.0%
0%20%40%60%80%100%

Percentile: 0.0%

CVSS

5.3medium3.x
0246810

CVSS Score: 5.3/10

All CVSS Scores

CVSS 3.x
5.3

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CVSS 2.0
4.3

Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Description

Уязвимость HTTP-сервера nginx связана с недостатками обработки HTTP-запросов. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, получить несанкционированный доступ к информации

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

bdu

Related Vulnerabilities

Exploits

Exploit ID: CVE-2019-20372

Source: github-poc

URL: https://github.com/moften/CVE-2019-20372

Recommendations

Source: bdu

Использование рекомендаций:https://github.com/kubernetes/ingress-nginx/pull/4859

http://nginx.org/en/CHANGES

https://github.com/nginx/nginx/commit/c1be55f97211d38b69ac0c2027e6812ab8b1b94e

Для программных продуктов Novell Inc.:
https://www.suse.com/security/cve/CVE-2019-20372

Для программных продуктов Red Hat Inc.:
https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2019-20372.xml

Для Ubuntu
https://ubuntu.com/security/CVE-2019-20372

Для Debian GNU/Linux:
https://security-tracker.debian.org/tracker/CVE-2019-20372

Для ОС ОН «Стрелец»:
Обновление программного обеспечения nginx до версии 1.10.3-1+deb9u7

URL: https://bdu.fstec.ru/vul/2022-02389

Vulnerable Software (36)

Type: Configuration

Vendor: apple inc.

Product: xcode

Operating System: debian gnu/linux 8

Trait:
{  "version_end_excluding": "13.0"}

Source: bdu

Type: Configuration

Vendor: apple inc.

Product: xcode

Operating System: debian gnu/linux 10

Trait:
{  "version_end_excluding": "13.0"}

Source: bdu

Type: Configuration

Vendor: apple inc.

Product: xcode

Operating System: ubuntu 19.10

Trait:
{  "version_end_excluding": "13.0"}

Source: bdu

Type: Configuration

Vendor: apple inc.

Product: xcode

Operating System: ubuntu 16.04 ESM

Trait:
{  "version_end_excluding": "13.0"}

Source: bdu

Type: Configuration

Vendor: apple inc.

Product: xcode

Operating System: debian gnu/linux 9

Trait:
{  "version_end_excluding": "13.0"}

Source: bdu

Type: Configuration

Vendor: apple inc.

Product: xcode

Operating System: ubuntu 19.04

Trait:
{  "version_end_excluding": "13.0"}

Source: bdu

Type: Configuration

Vendor: apple inc.

Product: xcode

Operating System: debian gnu/linux 11

Trait:
{  "version_end_excluding": "13.0"}

Source: bdu

Type: Configuration

Vendor: apple inc.

Product: xcode

Operating System: strelets *

Trait:
{  "version_end_excluding": "13.0"}

Source: bdu

Type: Configuration

Vendor: apple inc.

Product: xcode

Operating System: ubuntu 18.04 LTS

Trait:
{  "version_end_excluding": "13.0"}

Source: bdu

Type: Configuration

Vendor: apple inc.

Product: xcode

Operating System: red hat enterprise linux 8

Trait:
{  "version_end_excluding": "13.0"}

Source: bdu

Type: Configuration

Vendor: apple inc.

Product: xcode

Operating System: opensuse leap 15.1

Trait:
{  "version_end_excluding": "13.0"}

Source: bdu

Type: Configuration

Vendor: apple inc.

Product: xcode

Operating System: ubuntu 14.04 ESM

Trait:
{  "version_end_excluding": "13.0"}

Source: bdu

Type: Configuration

Vendor: nginx inc.

Product: nginx

Operating System: debian gnu/linux 8

Trait:
{  "version_end_excluding": "1.17.7"}

Source: bdu

Type: Configuration

Vendor: nginx inc.

Product: nginx

Operating System: ubuntu 16.04 ESM

Trait:
{  "version_end_excluding": "1.17.7"}

Source: bdu

Type: Configuration

Vendor: nginx inc.

Product: nginx

Operating System: debian gnu/linux 9

Trait:
{  "version_end_excluding": "1.17.7"}

Source: bdu

Type: Configuration

Vendor: nginx inc.

Product: nginx

Operating System: ubuntu 19.04

Trait:
{  "version_end_excluding": "1.17.7"}

Source: bdu

Type: Configuration

Vendor: nginx inc.

Product: nginx

Operating System: debian gnu/linux 11

Trait:
{  "version_end_excluding": "1.17.7"}

Source: bdu

Type: Configuration

Vendor: nginx inc.

Product: nginx

Operating System: ubuntu 18.04 LTS

Trait:
{  "version_end_excluding": "1.17.7"}

Source: bdu

Type: Configuration

Vendor: nginx inc.

Product: nginx

Operating System: red hat enterprise linux 8

Trait:
{  "version_end_excluding": "1.17.7"}

Source: bdu

Type: Configuration

Vendor: nginx inc.

Product: nginx

Operating System: ubuntu 14.04 ESM

Trait:
{  "version_end_excluding": "1.17.7"}

Source: bdu