Inconsistent interpretation of HTTP requests in NGINX Open Source - CVE-2019-20372
Published: January 13, 2020 / Updated: May 9, 2025
Vulnerability identifier: #VU24230
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-20372
CWE-ID: CWE-444
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote attacker to perform HTTP request smuggling attacks.
The vulnerability exists with certain error_page configurations. A remote attacker can read unauthorized web pages in environments where NGINX is being fronted by a load balancer.
Affected software
NGINX Open Source
nginx (Alpine package)
nginx (Ubuntu package)
nginx
rh-nginx116-nginx (Red Hat package)
Fedora
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Opensuse
Junos OS
Cisco Webex Video Mesh
Netcool Operations Insight
PowerFlex rack
Storage Protect Plus Server
nginx (Alpine package)
nginx (Ubuntu package)
nginx
rh-nginx116-nginx (Red Hat package)
Fedora
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Opensuse
Junos OS
Cisco Webex Video Mesh
Netcool Operations Insight
PowerFlex rack
Storage Protect Plus Server
How to mitigate CVE-2019-20372
Install updates from vendor's website.
NGINX Open Source - update to 1.17.7
nginx (Alpine package) - addressed in versions 1.14.2-r2, 1.14.2-r5
nginx (Ubuntu package) - addressed in versions 1.10.3-0ubuntu0.16.04.5, 1.14.0-0ubuntu1.7, 1.15.9-0ubuntu1.2, 1.16.1-0ubuntu2.1
Junos OS - addressed in versions 21.4R3-S8, 22.2R3-S5, 22.3R3-S3, 22.4R3-S4, 23.2R2-S2, 23.4R2-S1, 24.2R1
Cisco Webex Video Mesh - update to 2020.01.30.2115m
Netcool Operations Insight - update to 1.6.8
nginx - update to 1.16.1-2.el7
rh-nginx116-nginx (Red Hat package) - update to 1.16.1-4.el7.1
PowerFlex rack - update to 3.6.6.0
Storage Protect Plus Server - update to 10.1.16.2
nginx (Alpine package) - addressed in versions 1.14.2-r2, 1.14.2-r5
nginx (Ubuntu package) - addressed in versions 1.10.3-0ubuntu0.16.04.5, 1.14.0-0ubuntu1.7, 1.15.9-0ubuntu1.2, 1.16.1-0ubuntu2.1
Junos OS - addressed in versions 21.4R3-S8, 22.2R3-S5, 22.3R3-S3, 22.4R3-S4, 23.2R2-S2, 23.4R2-S1, 24.2R1
Cisco Webex Video Mesh - update to 2020.01.30.2115m
Netcool Operations Insight - update to 1.6.8
nginx - update to 1.16.1-2.el7
rh-nginx116-nginx (Red Hat package) - update to 1.16.1-4.el7.1
PowerFlex rack - update to 3.6.6.0
Storage Protect Plus Server - update to 10.1.16.2
Links to Public Exploits and PoC-codes
External References
- http://nginx.org/en/CHANGES
- https://bertjwregeer.keybase.pub/2019-12-10%20-%20error_page%20request%20smuggling.pdf
- https://duo.com/docs/dng-notes#version-1.5.4-january-2020
- https://github.com/kubernetes/ingress-nginx/pull/4859
- https://github.com/nginx/nginx/commit/c1be55f97211d38b69ac0c2027e6812ab8b1b94e
Related Security Bulletins
- HTTP request smuggling in Nginx
- Ubuntu update for nginx
- HTTP Request Smuggling in Cisco Webex Video Mesh
- OpenSUSE Linux update for nginx
- Inconsistent interpretation of HTTP requests in nginx (Alpine package)
- Red Hat Enterprise Linux 8 update for the nginx:1.16 module
- Red Hat Software Collections update for rh-nginx116-nginx
- Multiple vulnerabilities in IBM Netcool Operations Insight
- Multiple vulnerabilities in Dell PowerFlex Rack
- Multiple vulnerabilities in Dell PowerFlex Appliance
- Multiple vulnerabilities in Storage Protect Plus Server
- Junos OS update for nginx
- Fedora EPEL 7 update for nginx