CVE-2020-11724
Published Apr 12, 2020
·Updated
An issue was discovered in OpenResty before 1.15.8.4. ngx_http_lua_subrequest.c allows HTTP request smuggling, as demonstrated by the ngx.location.capture API.
Affected Software
5 affected componentsFixes available
debian/nginx<=1.10.3-1+deb9u3, <=1.10.3-1, <=1.14.2-2+deb10u1, <=1.18.0-4
1.18.0-51.14.2-2+deb10u3
debian/nginx
1.18.0-6.1+deb11u31.22.1-91.26.0-3
OpenResty OpenResty<1.15.8.4
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Remediation
Event History
Apr 12, 2020
CVE Published
via MITRE·08:55 PM
Data Sourced
via MITRE·08:55 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·11:37 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·01:45 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-11724.
2
What is the title of the vulnerability?
The title of the vulnerability is 'An issue was discovered in OpenResty before 1.15.8.4. ngx_http_lua_subrequest.c allows HTTP request smuggling.'
3
What is the affected software?
The affected software is OpenResty before version 1.15.8.4.
4
What is the severity of CVE-2020-11724?
The severity of CVE-2020-11724 is not specified.
5
How do I fix the CVE-2020-11724 vulnerability?
To fix the CVE-2020-11724 vulnerability, update to OpenResty version 1.15.8.4 or later.