Origin validation error in NGINX Open Source - CVE-2021-3618
Published: January 9, 2022
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to a logic error in TLS implementation when handling different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A remote attacker with ability to perform TCP/IP layer MitM attack can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.
This attack technique was dubbed ALPACA (application layer protocol content confusion
attack).
Affected software
Amazon Linux AMI
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
SUSE Linux Enterprise Storage
Oracle Solaris
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Server Applications
openSUSE Leap
Ubuntu
openEuler
Junos OS
Fedora
vsftpd
Netcool Operations Insight
Spectrum Discover
IBM Cloud Automation Manager
IBM Observability with Instana
IBM Watson Discovery for IBM Cloud Pak for Data
Dell Secure Connect Gateway
VMware Tanzu Operations Manager
Sendmail
nginx-extras (Ubuntu package)
nginx-core (Ubuntu package)
nginx-full (Ubuntu package)
nginx-light (Ubuntu package)
libnginx-mod-http-lua (Ubuntu package)
nginx
nginx-debuginfo
nginx-debugsource
nginx-source
vim-plugin-nginx
nginx-help
nginx-mod-http-perl
nginx-mod-http-image-filter
nginx-mod-http-xslt-filter
nginx-mod-mail
nginx-mod-stream
nginx-all-modules
nginx-filesystem
vsftpd
vsftpd (Ubuntu package)
vsftpd-debuginfo
vsftpd-debugsource
sendmail
PowerFlex rack
Watson Studio on Cloud Pak for Data
Robotic Process Automation for Cloud Pak
HPE Moonshot 1500 Chassis Manager
How to mitigate CVE-2021-3618
vsftpd - update to 3.0.4
Netcool Operations Insight - update to 1.6.15
VMware Tanzu Operations Manager - addressed in versions 2.7.25, 2.8.16, 2.9.12, 2.10.3
IBM Cloud Automation Manager - update to 4.2.0.1 iFix 4
Sendmail - update to 8.17.1
Junos OS - addressed in versions 21.4R3-S8, 22.2R3-S5, 22.3R3-S3, 22.4R3-S4, 23.2R2-S2, 23.4R2-S1, 24.2R1
IBM Observability with Instana - update to 279
nginx-extras (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.14.0-0ubuntu1.10, 1.18.0-0ubuntu1.3, 1.18.0-6ubuntu11.1, 1.18.0-6ubuntu14.1
nginx-core (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.14.0-0ubuntu1.10, 1.18.0-0ubuntu1.3, 1.18.0-6ubuntu11.1, 1.18.0-6ubuntu14.1
nginx-full (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.14.0-0ubuntu1.10, 1.18.0-0ubuntu1.3
nginx-light (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.14.0-0ubuntu1.10, 1.18.0-0ubuntu1.3, 1.18.0-6ubuntu11.1, 1.18.0-6ubuntu14.1
libnginx-mod-http-lua (Ubuntu package) - addressed in versions 1.14.0-0ubuntu1.10, 1.18.0-0ubuntu1.3
nginx - addressed in versions 1.16.1-150000.3.18.1, 1.16.1-150100.6.16.1, 1.16.1-150200.3.9.1, 1.19.8-150300.3.9.1
nginx-debuginfo - addressed in versions 1.16.1-150000.3.18.1, 1.16.1-150100.6.16.1, 1.16.1-150200.3.9.1, 1.19.8-150300.3.9.1
nginx-debugsource - addressed in versions 1.16.1-150000.3.18.1, 1.16.1-150100.6.16.1, 1.16.1-150200.3.9.1, 1.19.8-150300.3.9.1
nginx-source - addressed in versions 1.16.1-150100.6.16.1, 1.16.1-150200.3.9.1, 1.19.8-150300.3.9.1
vim-plugin-nginx - update to 1.19.8-150300.3.9.1
nginx - addressed in versions 1.20.1-3.fc33, 1.20.1-3.fc34, 1.20-3320210625014643.601d93de
nginx-help - update to 1.21.5-1
nginx-mod-http-perl - update to 1.21.5-1
nginx-mod-http-image-filter - update to 1.21.5-1
nginx-debugsource - update to 1.21.5-1
nginx-debuginfo - update to 1.21.5-1
nginx - update to 1.21.5-1
nginx-mod-http-xslt-filter - update to 1.21.5-1
nginx-mod-mail - update to 1.21.5-1
nginx-mod-stream - update to 1.21.5-1
nginx-all-modules - update to 1.21.5-1
nginx-filesystem - update to 1.21.5-1
nginx - update to 1.22.1-1
vsftpd - addressed in versions 3.0.3-43.fc34, 3.0.3-46.fc35
vsftpd (Ubuntu package) - update to 3.0.5-0ubuntu0.20.04.1
vsftpd - update to 3.0.5-1
vsftpd-debuginfo - addressed in versions 3.0.5-47.7.1, 3.0.5-51.1, 3.0.5-150000.7.19.1, 3.0.5-150200.12.9.1, 3.0.5-150400.3.3.1
vsftpd-debugsource - addressed in versions 3.0.5-47.7.1, 3.0.5-51.1, 3.0.5-150000.7.19.1, 3.0.5-150200.12.9.1, 3.0.5-150400.3.3.1
vsftpd - addressed in versions 3.0.5-47.7.1, 3.0.5-51.1, 3.0.5-150000.7.19.1, 3.0.5-150200.12.9.1, 3.0.5-150400.3.3.1
PowerFlex rack - update to 3.6.6.0
HPE Moonshot 1500 Chassis Manager - update to 4.0-b43
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.5.1
Watson Studio on Cloud Pak for Data - addressed in versions 4.8.7, 5.1.0
Dell Secure Connect Gateway - update to 5.14.00.16
sendmail - update to 8.17.1-5
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.7, 23.0.8
External References
Related Security Bulletins
- Security restrictions bypass in nginx
- Security restrictions bypass in vsftpd
- Security restrictions bypass in Sendmail
- Multiple vulnerabilities in Spectrum Discover
- Ubuntu update for nginx
- Ubuntu update for nginx
- VMware Tanzu Operations Manager update for nginx
- Security restrictions bypass in IBM Watson Discovery for IBM Cloud Pak for Data
- Security restrictions bypass in IBM Cloud Automation Manager
- SUSE update for vsftpd
- SUSE update for vsftpd
- SUSE update for vsftpd
- SUSE update for vsftpd
- Ubuntu update for nginx
- SUSE update for vsftpd
- SUSE update for nginx
- SUSE update for nginx
- SUSE update for nginx
- SUSE update for nginx
- Multiple vulnerabilities in Dell Secure Connect Gateway
- Origin validation error in IBM Cloud Automation Manager
- Multiple vulnerabilities in Oracle Solaris third-party software
- Origin validation error in IBM Robotic Process Automation for Cloud Pak
- Ubuntu update for vsftpd
- openEuler update for nginx
- Multiple vulnerabilities in Dell PowerFlex Rack
- Multiple vulnerabilities in Dell PowerFlex Appliance
- Amazon Linux AMI update for sendmail
- Amazon Linux AMI update for vsftpd
- Amazon Linux AMI update for nginx
- Multiple vulnerabilities in IBM Observability with Instana
- Multiple vulnerabilities in HPE Moonshot 1500 Chassis Manager
- Junos OS update for nginx
- Fedora 33 update for nginx
- Fedora 34 update for nginx
- Fedora 33 Modular update for nginx
- Fedora 34 update for vsftpd
- Fedora 35 update for vsftpd
- Multiple vulnerabilities in IBM Watson Studio on Cloud Pak for Data
- Multiple vulnerabilities in Netcool Operations Insight