CVE-2020-11724: High severity OpenResty OpenResty vulnerability
Published Apr 12, 2020
·Updated
An issue was discovered in OpenResty before 1.15.8.4. ngxhttpluasubrequest.c allows HTTP request smuggling, as demonstrated by the ngx.location.capture API.
Affected Software
5 affected componentsFixes available
debian/nginx<=1.10.3-1+deb9u3, <=1.10.3-1, <=1.14.2-2+deb10u1, <=1.18.0-4
1.18.0-51.14.2-2+deb10u3
debian/nginx
1.18.0-6.1+deb11u31.22.1-91.26.0-3
OpenResty OpenResty<1.15.8.4
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Remediation
Event History
Apr 12, 2020
CVE Published
via MITRE·08:55 PM
Data Sourced
via MITRE·08:55 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·11:37 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·01:45 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-11724.
2
What is the title of the vulnerability?
The title of the vulnerability is 'An issue was discovered in OpenResty before 1.15.8.4. ngx_http_lua_subrequest.c allows HTTP request smuggling.'
3
What is the affected software?
The affected software is OpenResty before version 1.15.8.4.
4
What is the severity of CVE-2020-11724?
The severity of CVE-2020-11724 is not specified.
5
How do I fix the CVE-2020-11724 vulnerability?
To fix the CVE-2020-11724 vulnerability, update to OpenResty version 1.15.8.4 or later.