Origin validation error in NGINX Open Source - CVE-2021-3618

 

Origin validation error in NGINX Open Source - CVE-2021-3618

Published: January 9, 2022


Vulnerability identifier: #VU59319
CSH Severity: Medium
CVSS v4 BT: 6.9 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2021-3618
CWE-ID: CWE-346
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to a logic error in TLS implementation when handling different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A remote attacker with ability to perform TCP/IP layer MitM attack can redirect traffic from one subdomain to another, resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.

This attack technique was dubbed ALPACA (application layer protocol content confusion attack).


Affected software

NGINX Open Source
Amazon Linux AMI
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
SUSE Linux Enterprise Storage
Oracle Solaris
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Server Applications
openSUSE Leap
Ubuntu
openEuler
Junos OS
Fedora
vsftpd
Netcool Operations Insight
Spectrum Discover
IBM Cloud Automation Manager
IBM Observability with Instana
IBM Watson Discovery for IBM Cloud Pak for Data
Dell Secure Connect Gateway
VMware Tanzu Operations Manager
Sendmail
nginx-extras (Ubuntu package)
nginx-core (Ubuntu package)
nginx-full (Ubuntu package)
nginx-light (Ubuntu package)
libnginx-mod-http-lua (Ubuntu package)
nginx
nginx-debuginfo
nginx-debugsource
nginx-source
vim-plugin-nginx
nginx-help
nginx-mod-http-perl
nginx-mod-http-image-filter
nginx-mod-http-xslt-filter
nginx-mod-mail
nginx-mod-stream
nginx-all-modules
nginx-filesystem
vsftpd
vsftpd (Ubuntu package)
vsftpd-debuginfo
vsftpd-debugsource
sendmail
PowerFlex rack
Watson Studio on Cloud Pak for Data
Robotic Process Automation for Cloud Pak
HPE Moonshot 1500 Chassis Manager

How to mitigate CVE-2021-3618

Install updates from vendor's website.

NGINX Open Source - update to 1.21.0
vsftpd - update to 3.0.4
Netcool Operations Insight - update to 1.6.15
VMware Tanzu Operations Manager - addressed in versions 2.7.25, 2.8.16, 2.9.12, 2.10.3
IBM Cloud Automation Manager - update to 4.2.0.1 iFix 4
Sendmail - update to 8.17.1
Junos OS - addressed in versions 21.4R3-S8, 22.2R3-S5, 22.3R3-S3, 22.4R3-S4, 23.2R2-S2, 23.4R2-S1, 24.2R1
IBM Observability with Instana - update to 279
nginx-extras (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.14.0-0ubuntu1.10, 1.18.0-0ubuntu1.3, 1.18.0-6ubuntu11.1, 1.18.0-6ubuntu14.1
nginx-core (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.14.0-0ubuntu1.10, 1.18.0-0ubuntu1.3, 1.18.0-6ubuntu11.1, 1.18.0-6ubuntu14.1
nginx-full (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.14.0-0ubuntu1.10, 1.18.0-0ubuntu1.3
nginx-light (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.14.0-0ubuntu1.10, 1.18.0-0ubuntu1.3, 1.18.0-6ubuntu11.1, 1.18.0-6ubuntu14.1
libnginx-mod-http-lua (Ubuntu package) - addressed in versions 1.14.0-0ubuntu1.10, 1.18.0-0ubuntu1.3
nginx - addressed in versions 1.16.1-150000.3.18.1, 1.16.1-150100.6.16.1, 1.16.1-150200.3.9.1, 1.19.8-150300.3.9.1
nginx-debuginfo - addressed in versions 1.16.1-150000.3.18.1, 1.16.1-150100.6.16.1, 1.16.1-150200.3.9.1, 1.19.8-150300.3.9.1
nginx-debugsource - addressed in versions 1.16.1-150000.3.18.1, 1.16.1-150100.6.16.1, 1.16.1-150200.3.9.1, 1.19.8-150300.3.9.1
nginx-source - addressed in versions 1.16.1-150100.6.16.1, 1.16.1-150200.3.9.1, 1.19.8-150300.3.9.1
vim-plugin-nginx - update to 1.19.8-150300.3.9.1
nginx - addressed in versions 1.20.1-3.fc33, 1.20.1-3.fc34, 1.20-3320210625014643.601d93de
nginx-help - update to 1.21.5-1
nginx-mod-http-perl - update to 1.21.5-1
nginx-mod-http-image-filter - update to 1.21.5-1
nginx-debugsource - update to 1.21.5-1
nginx-debuginfo - update to 1.21.5-1
nginx - update to 1.21.5-1
nginx-mod-http-xslt-filter - update to 1.21.5-1
nginx-mod-mail - update to 1.21.5-1
nginx-mod-stream - update to 1.21.5-1
nginx-all-modules - update to 1.21.5-1
nginx-filesystem - update to 1.21.5-1
nginx - update to 1.22.1-1
vsftpd - addressed in versions 3.0.3-43.fc34, 3.0.3-46.fc35
vsftpd (Ubuntu package) - update to 3.0.5-0ubuntu0.20.04.1
vsftpd - update to 3.0.5-1
vsftpd-debuginfo - addressed in versions 3.0.5-47.7.1, 3.0.5-51.1, 3.0.5-150000.7.19.1, 3.0.5-150200.12.9.1, 3.0.5-150400.3.3.1
vsftpd-debugsource - addressed in versions 3.0.5-47.7.1, 3.0.5-51.1, 3.0.5-150000.7.19.1, 3.0.5-150200.12.9.1, 3.0.5-150400.3.3.1
vsftpd - addressed in versions 3.0.5-47.7.1, 3.0.5-51.1, 3.0.5-150000.7.19.1, 3.0.5-150200.12.9.1, 3.0.5-150400.3.3.1
PowerFlex rack - update to 3.6.6.0
HPE Moonshot 1500 Chassis Manager - update to 4.0-b43
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.5.1
Watson Studio on Cloud Pak for Data - addressed in versions 4.8.7, 5.1.0
Dell Secure Connect Gateway - update to 5.14.00.16
sendmail - update to 8.17.1-5
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.7, 23.0.8

External References

Related Security Bulletins