Improper access control in NGINX Open Source - CVE-2014-3616
Published: December 8, 2014 / Updated: July 28, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to manipulate data.
nginx 0.5.6 through 1.7.4, when using the same shared ssl_session_cache or ssl_session_ticket_key for multiple servers, can reuse a cached SSL session for an unrelated context, which allows remote attackers with certain privileges to conduct "virtual host confusion" attacks.
Affected software
Amazon Linux AMI
Gentoo Linux
Fedora
nginx (Alpine package)
nginx
How to mitigate CVE-2014-3616
nginx (Alpine package) - update to 1.6.2-r0
nginx - addressed in versions 1.0.15-8.el6, 1.0.15-10.el6, 1.6.2-1.el7, 1.6.2-2.fc21