Improper authentication in NGINX Plus and NGINX Open Source - CVE-2025-23419

 

Improper authentication in NGINX Plus and NGINX Open Source - CVE-2025-23419

Published: February 6, 2025 / Updated: February 11, 2025


Vulnerability identifier: #VU103686
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-23419
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an TLS session resumption when handling client certificate authentication. A remote attacker can bypass authentication process and gain unauthorized access to the application.

Successful exploitation of the vulnerability requires that name-based virtual hosts are configured to share the same IP address and port combination and have TLS 1.3 and OpenSSL. This vulnerability arises when TLS session tickets are used and/or the SSL session cache is used in the default virtual server and the default virtual server is performing client certificate authentication.


Affected software

NGINX Plus
NGINX Open Source
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
Server Applications Module
openSUSE Leap
openEuler
Ubuntu
Anolis OS
Fedora
Netezza Appliance
DataStage on Cloud Pak for Data
Maximo Application Suite - Visual Inspection Component
Netezza Performance Server Replication Services
SmartFabric OS10
Cloud Pak for Data System - Cyclops
EasyApache
Session Smart Router
nginx-mod-vts
nginx-mod-fancyindex
nginx-mod-modsecurity
nginx-mod-naxsi
nginx-core (Ubuntu package)
nginx-doc (Ubuntu package)
nginx-common (Ubuntu package)
nginx-extras (Ubuntu package)
nginx-full (Ubuntu package)
nginx-light (Ubuntu package)
nginx (Ubuntu package)
libnginx-mod-rtmp (Ubuntu package)
nginx
nginx-debuginfo
nginx-debugsource
vim-plugin-nginx
nginx-source
nginx-help
nginx-filesystem
nginx-mod-devel
nginx-all-modules
nginx-mod-http-image-filter
nginx-mod-http-perl
nginx-mod-stream
nginx-mod-http-xslt-filter
nginx-mod-mail
nginx-dev (Ubuntu package)
nginx-core
nginx-doc

How to mitigate CVE-2025-23419

Install updates from vendor's website.

NGINX Plus - addressed in versions R32 P2, R33 P2
NGINX Open Source - addressed in versions 1.26.3, 1.27.4
Netezza Appliance - update to 1.0.0.1
EasyApache - update to 4 25-5
DataStage on Cloud Pak for Data - update to 5.3.1 patch 3
Maximo Application Suite - Visual Inspection Component - addressed in versions 9.0.17, 9.1.6
nginx-mod-vts - addressed in versions 0.2.3-3.fc40, 0.2.3-3.fc41, 0.2.3-3.fc42
nginx-mod-fancyindex - addressed in versions 0.5.2-8.fc40, 0.5.2-10.fc41, 0.5.2-10.fc42
nginx-mod-modsecurity - addressed in versions 1.0.3-16.fc40, 1.0.3-16.fc41, 1.0.3-16.fc42
nginx-mod-naxsi - addressed in versions 1.6-9.fc40, 1.6-9.fc41, 1.6-9.fc42
nginx-core (Ubuntu package) - addressed in versions 1.18.0-0ubuntu1.7, 1.18.0-6ubuntu14.6, 1.24.0-2ubuntu7.3, 1.26.0-2ubuntu3.2
nginx-doc (Ubuntu package) - addressed in versions 1.18.0-0ubuntu1.7, 1.18.0-6ubuntu14.6, 1.26.0-2ubuntu3.2
nginx-common (Ubuntu package) - addressed in versions 1.18.0-0ubuntu1.7, 1.18.0-6ubuntu14.6, 1.24.0-2ubuntu7.3, 1.26.0-2ubuntu3.2
nginx-extras (Ubuntu package) - addressed in versions 1.18.0-0ubuntu1.7, 1.18.0-6ubuntu14.6, 1.24.0-2ubuntu7.3, 1.26.0-2ubuntu3.2
nginx-full (Ubuntu package) - addressed in versions 1.18.0-0ubuntu1.7, 1.18.0-6ubuntu14.6, 1.24.0-2ubuntu7.3, 1.26.0-2ubuntu3.2
nginx-light (Ubuntu package) - addressed in versions 1.18.0-0ubuntu1.7, 1.18.0-6ubuntu14.6, 1.24.0-2ubuntu7.3, 1.26.0-2ubuntu3.2
nginx (Ubuntu package) - addressed in versions 1.18.0-0ubuntu1.7, 1.18.0-6ubuntu14.6, 1.24.0-2ubuntu7.3, 1.26.0-2ubuntu3.2
libnginx-mod-rtmp (Ubuntu package) - addressed in versions 1.18.0-0ubuntu1.7, 1.18.0-6ubuntu14.6
nginx - addressed in versions 1.19.8-150300.3.18.1, 1.21.5-150400.3.12.1, 1.21.5-150600.10.12.1
nginx-debuginfo - addressed in versions 1.19.8-150300.3.18.1, 1.21.5-150400.3.12.1, 1.21.5-150600.10.12.1
nginx-debugsource - addressed in versions 1.19.8-150300.3.18.1, 1.21.5-150400.3.12.1, 1.21.5-150600.10.12.1
vim-plugin-nginx - update to 1.19.8-150300.3.18.1
nginx-source - addressed in versions 1.19.8-150300.3.18.1, 1.21.5-150400.3.12.1, 1.21.5-150600.10.12.1
nginx-debuginfo - update to 1.24.0-3
nginx-help - update to 1.24.0-3
nginx-filesystem - update to 1.24.0-3
nginx - update to 1.24.0-3
nginx-debugsource - update to 1.24.0-3
nginx-mod-devel - update to 1.24.0-3
nginx-all-modules - update to 1.24.0-3
nginx-mod-http-image-filter - update to 1.24.0-3
nginx-mod-http-perl - update to 1.24.0-3
nginx-mod-stream - update to 1.24.0-3
nginx-mod-http-xslt-filter - update to 1.24.0-3
nginx-mod-mail - update to 1.24.0-3
nginx-dev (Ubuntu package) - update to 1.26.0-2ubuntu3.2
nginx - update to 1.26.2-2
nginx-mod-devel - update to 1.26.2-2
nginx-core - update to 1.26.2-2
nginx-filesystem - update to 1.26.2-2
nginx-doc - update to 1.26.2-2
nginx-all-modules - update to 1.26.2-2
nginx-mod-stream - update to 1.26.2-2
nginx-mod-mail - update to 1.26.2-2
nginx-mod-http-xslt-filter - update to 1.26.2-2
nginx-mod-http-perl - update to 1.26.2-2
nginx-mod-http-image-filter - update to 1.26.2-2
nginx - addressed in versions 1.26.3-1.fc40, 1.26.3-1.fc41, 1.26.3-1.fc42
Netezza Performance Server Replication Services - update to 3.0.5.1
Session Smart Router - addressed in versions 6.2.10, 6.3.7
SmartFabric OS10 - update to 10.6.0.3
Cloud Pak for Data System - Cyclops - update to 11.3.1.1

External References

Related Security Bulletins