Improper access control in NGINX Open Source - CVE-2014-3616

 

Improper access control in NGINX Open Source - CVE-2014-3616

Published: December 8, 2014 / Updated: July 28, 2020


Vulnerability identifier: #VU32495
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-3616
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to manipulate data.

nginx 0.5.6 through 1.7.4, when using the same shared ssl_session_cache or ssl_session_ticket_key for multiple servers, can reuse a cached SSL session for an unrelated context, which allows remote attackers with certain privileges to conduct "virtual host confusion" attacks.


Affected software

NGINX Open Source
Amazon Linux AMI
Gentoo Linux
Fedora
nginx (Alpine package)
nginx

How to mitigate CVE-2014-3616

Install update from vendor's website.

NGINX Open Source - update to 1.7.5
nginx (Alpine package) - update to 1.6.2-r0
nginx - addressed in versions 1.0.15-8.el6, 1.0.15-10.el6, 1.6.2-1.el7, 1.6.2-2.fc21

External References

Related Security Bulletins