Improper authentication in NGINX Plus and NGINX Open Source - CVE-2025-23419
Published: February 6, 2025 / Updated: February 11, 2025
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an TLS session resumption when handling client certificate authentication. A remote attacker can bypass authentication process and gain unauthorized access to the application.
Successful exploitation of the vulnerability requires that name-based virtual hosts are configured to share the same IP address and port combination and have TLS 1.3 and OpenSSL. This vulnerability arises when TLS session tickets are used and/or the SSL session cache is used in the default virtual server and the default virtual server is performing client certificate authentication.
Affected software
NGINX Open Source
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
Server Applications Module
openSUSE Leap
openEuler
Ubuntu
Anolis OS
Fedora
Netezza Appliance
DataStage on Cloud Pak for Data
Maximo Application Suite - Visual Inspection Component
Netezza Performance Server Replication Services
SmartFabric OS10
Cloud Pak for Data System - Cyclops
EasyApache
Session Smart Router
nginx-mod-vts
nginx-mod-fancyindex
nginx-mod-modsecurity
nginx-mod-naxsi
nginx-core (Ubuntu package)
nginx-doc (Ubuntu package)
nginx-common (Ubuntu package)
nginx-extras (Ubuntu package)
nginx-full (Ubuntu package)
nginx-light (Ubuntu package)
nginx (Ubuntu package)
libnginx-mod-rtmp (Ubuntu package)
nginx
nginx-debuginfo
nginx-debugsource
vim-plugin-nginx
nginx-source
nginx-help
nginx-filesystem
nginx-mod-devel
nginx-all-modules
nginx-mod-http-image-filter
nginx-mod-http-perl
nginx-mod-stream
nginx-mod-http-xslt-filter
nginx-mod-mail
nginx-dev (Ubuntu package)
nginx-core
nginx-doc
How to mitigate CVE-2025-23419
NGINX Open Source - addressed in versions 1.26.3, 1.27.4
Netezza Appliance - update to 1.0.0.1
EasyApache - update to 4 25-5
DataStage on Cloud Pak for Data - update to 5.3.1 patch 3
Maximo Application Suite - Visual Inspection Component - addressed in versions 9.0.17, 9.1.6
nginx-mod-vts - addressed in versions 0.2.3-3.fc40, 0.2.3-3.fc41, 0.2.3-3.fc42
nginx-mod-fancyindex - addressed in versions 0.5.2-8.fc40, 0.5.2-10.fc41, 0.5.2-10.fc42
nginx-mod-modsecurity - addressed in versions 1.0.3-16.fc40, 1.0.3-16.fc41, 1.0.3-16.fc42
nginx-mod-naxsi - addressed in versions 1.6-9.fc40, 1.6-9.fc41, 1.6-9.fc42
nginx-core (Ubuntu package) - addressed in versions 1.18.0-0ubuntu1.7, 1.18.0-6ubuntu14.6, 1.24.0-2ubuntu7.3, 1.26.0-2ubuntu3.2
nginx-doc (Ubuntu package) - addressed in versions 1.18.0-0ubuntu1.7, 1.18.0-6ubuntu14.6, 1.26.0-2ubuntu3.2
nginx-common (Ubuntu package) - addressed in versions 1.18.0-0ubuntu1.7, 1.18.0-6ubuntu14.6, 1.24.0-2ubuntu7.3, 1.26.0-2ubuntu3.2
nginx-extras (Ubuntu package) - addressed in versions 1.18.0-0ubuntu1.7, 1.18.0-6ubuntu14.6, 1.24.0-2ubuntu7.3, 1.26.0-2ubuntu3.2
nginx-full (Ubuntu package) - addressed in versions 1.18.0-0ubuntu1.7, 1.18.0-6ubuntu14.6, 1.24.0-2ubuntu7.3, 1.26.0-2ubuntu3.2
nginx-light (Ubuntu package) - addressed in versions 1.18.0-0ubuntu1.7, 1.18.0-6ubuntu14.6, 1.24.0-2ubuntu7.3, 1.26.0-2ubuntu3.2
nginx (Ubuntu package) - addressed in versions 1.18.0-0ubuntu1.7, 1.18.0-6ubuntu14.6, 1.24.0-2ubuntu7.3, 1.26.0-2ubuntu3.2
libnginx-mod-rtmp (Ubuntu package) - addressed in versions 1.18.0-0ubuntu1.7, 1.18.0-6ubuntu14.6
nginx - addressed in versions 1.19.8-150300.3.18.1, 1.21.5-150400.3.12.1, 1.21.5-150600.10.12.1
nginx-debuginfo - addressed in versions 1.19.8-150300.3.18.1, 1.21.5-150400.3.12.1, 1.21.5-150600.10.12.1
nginx-debugsource - addressed in versions 1.19.8-150300.3.18.1, 1.21.5-150400.3.12.1, 1.21.5-150600.10.12.1
vim-plugin-nginx - update to 1.19.8-150300.3.18.1
nginx-source - addressed in versions 1.19.8-150300.3.18.1, 1.21.5-150400.3.12.1, 1.21.5-150600.10.12.1
nginx-debuginfo - update to 1.24.0-3
nginx-help - update to 1.24.0-3
nginx-filesystem - update to 1.24.0-3
nginx - update to 1.24.0-3
nginx-debugsource - update to 1.24.0-3
nginx-mod-devel - update to 1.24.0-3
nginx-all-modules - update to 1.24.0-3
nginx-mod-http-image-filter - update to 1.24.0-3
nginx-mod-http-perl - update to 1.24.0-3
nginx-mod-stream - update to 1.24.0-3
nginx-mod-http-xslt-filter - update to 1.24.0-3
nginx-mod-mail - update to 1.24.0-3
nginx-dev (Ubuntu package) - update to 1.26.0-2ubuntu3.2
nginx - update to 1.26.2-2
nginx-mod-devel - update to 1.26.2-2
nginx-core - update to 1.26.2-2
nginx-filesystem - update to 1.26.2-2
nginx-doc - update to 1.26.2-2
nginx-all-modules - update to 1.26.2-2
nginx-mod-stream - update to 1.26.2-2
nginx-mod-mail - update to 1.26.2-2
nginx-mod-http-xslt-filter - update to 1.26.2-2
nginx-mod-http-perl - update to 1.26.2-2
nginx-mod-http-image-filter - update to 1.26.2-2
nginx - addressed in versions 1.26.3-1.fc40, 1.26.3-1.fc41, 1.26.3-1.fc42
Netezza Performance Server Replication Services - update to 3.0.5.1
Session Smart Router - addressed in versions 6.2.10, 6.3.7
SmartFabric OS10 - update to 10.6.0.3
Cloud Pak for Data System - Cyclops - update to 11.3.1.1
External References
Related Security Bulletins
- TLS session resumption in NGINX and NGINX Plus
- Fedora 42 update for nginx, nginx-mod-fancyindex, nginx-mod-modsecurity, nginx-mod-naxsi, nginx-mod-vts
- Fedora 41 update for nginx, nginx-mod-fancyindex, nginx-mod-modsecurity, nginx-mod-naxsi, nginx-mod-vts
- Fedora 40 update for nginx, nginx-mod-fancyindex, nginx-mod-modsecurity, nginx-mod-naxsi, nginx-mod-vts
- openEuler update for nginx
- Multiple vulnerabilities in cPanel EasyApache
- Ubuntu update for nginx
- Ubuntu update for nginx
- Multiple vulnerabilities in Dell Networking OS10
- Anolis OS update for nginx
- SUSE update for nginx
- SUSE update for nginx
- SUSE update for nginx
- IBM Netezza Appliance update for nginx
- Multiple vulnerabilities in IBM Maximo Application Suite - Visual Inspection Component
- Juniper Session Smart Router update for third-party components
- Multiple vulnerabilities in IBM Netezza Performance Server Replication Services
- Multiple vulnerabilities in IBM Cloud Pak for Data System - Cyclops
- Multiple vulnerabilities in IBM DataStage on Cloud Pak for Data