This site is deprecated. Please
CLICK HERE for latest updates
Short Name |
HTTP:NGINX-RQST-URI-SECBYPASS
|
Severity |
Major
|
Recommended |
No
|
Recommended Action |
Drop
|
Category |
HTTP
|
Keywords |
Nginx Request URI Verification Security Bypass
|
Release Date |
2014/02/18
|
Update Number |
2346
|
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+
|
HTTP: Nginx Request URI Verification Security Bypass
This signature detects attempts to exploit a known vulnerability in Nginx. The vulnerability is caused by improper handling of unescaped space characters within URIs. A successful attack could bypass security restrictions in certain configurations.
Extended Description
nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescaped space character in a URI.
Affected Products
- Nginx nginx 0.8.41
- Nginx nginx 0.8.42
- Nginx nginx 0.8.43
- Nginx nginx 0.8.44
- Nginx nginx 0.8.45
- Nginx nginx 0.8.46
- Nginx nginx 0.8.47
- Nginx nginx 0.8.48
- Nginx nginx 0.8.49
- Nginx nginx 0.8.5
- Nginx nginx 0.8.50
- Nginx nginx 0.8.51
- Nginx nginx 0.8.52
- Nginx nginx 0.8.53
- Nginx nginx 0.8.6
- Nginx nginx 0.8.7
- Nginx nginx 0.8.8
- Nginx nginx 0.8.9
- Nginx nginx 0.9.0
- Nginx nginx 0.9.1
- Nginx nginx 0.9.2
- Nginx nginx 0.9.3
- Nginx nginx 0.9.4
- Nginx nginx 0.9.5
- Nginx nginx 0.9.6
- Nginx nginx 0.9.7
- Nginx nginx 1.0.0
- Nginx nginx 1.0.1
- Nginx nginx 1.0.10
- Nginx nginx 1.0.11
- Nginx nginx 1.0.12
- Nginx nginx 1.0.13
- Nginx nginx 1.0.14
- Nginx nginx 1.0.15
- Nginx nginx 1.0.2
- Nginx nginx 1.0.3
- Nginx nginx 1.0.4
- Nginx nginx 1.0.5
- Nginx nginx 1.0.6
- Nginx nginx 1.0.7
- Nginx nginx 1.0.8
- Nginx nginx 1.0.9
- Nginx nginx 1.1.0
- Nginx nginx 1.1.1
- Nginx nginx 1.1.10
- Nginx nginx 1.1.11
- Nginx nginx 1.1.12
- Nginx nginx 1.1.13
- Nginx nginx 1.1.14
- Nginx nginx 1.1.15
- Nginx nginx 1.1.16
- Nginx nginx 1.1.17
- Nginx nginx 1.1.18
- Nginx nginx 1.1.19
- Nginx nginx 1.1.2
- Nginx nginx 1.1.3
- Nginx nginx 1.1.4
- Nginx nginx 1.1.5
- Nginx nginx 1.1.6
- Nginx nginx 1.1.7
- Nginx nginx 1.1.8
- Nginx nginx 1.1.9
- Nginx nginx 1.2.0
- Nginx nginx 1.3.0
- Nginx nginx 1.3.1
- Nginx nginx 1.3.10
- Nginx nginx 1.3.11
- Nginx nginx 1.3.12
- Nginx nginx 1.3.13
- Nginx nginx 1.3.14
- Nginx nginx 1.3.15
- Nginx nginx 1.3.16
- Nginx nginx 1.3.2
- Nginx nginx 1.3.3
- Nginx nginx 1.3.4
- Nginx nginx 1.3.5
- Nginx nginx 1.3.6
- Nginx nginx 1.3.7
- Nginx nginx 1.3.8
- Nginx nginx 1.3.9
- Nginx nginx 1.4.0
- Nginx nginx 1.4.1
- Nginx nginx 1.4.2
- Nginx nginx 1.4.3
- Nginx nginx 1.5.0
- Nginx nginx 1.5.1
- Nginx nginx 1.5.2
- Nginx nginx 1.5.3
- Nginx nginx 1.5.4
- Nginx nginx 1.5.5
- Nginx nginx 1.5.6
References