Input validation error in lua-nginx-module - CVE-2020-36309
Published: April 14, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to insufficient validation of user-supplied input when processing URI in HTTP requests. A remote attacker can send a specially crafted HTTP request to the server and modify its response. As a result, an attacker can perform spoofing attack.
Affected software
VMware Tanzu Operations Manager
Ubuntu
nginx-light (Ubuntu package)
nginx-full (Ubuntu package)
nginx-core (Ubuntu package)
nginx-extras (Ubuntu package)
libnginx-mod-http-lua (Ubuntu package)
How to mitigate CVE-2020-36309
VMware Tanzu Operations Manager - addressed in versions 2.7.25, 2.8.16, 2.9.12, 2.10.3
nginx-light (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.14.0-0ubuntu1.10, 1.18.0-0ubuntu1.3, 1.18.0-6ubuntu11.1, 1.18.0-6ubuntu14.1
nginx-full (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.14.0-0ubuntu1.10, 1.18.0-0ubuntu1.3
nginx-core (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.14.0-0ubuntu1.10, 1.18.0-0ubuntu1.3, 1.18.0-6ubuntu11.1, 1.18.0-6ubuntu14.1
nginx-extras (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.14.0-0ubuntu1.10, 1.18.0-0ubuntu1.3, 1.18.0-6ubuntu11.1, 1.18.0-6ubuntu14.1
libnginx-mod-http-lua (Ubuntu package) - addressed in versions 1.14.0-0ubuntu1.10, 1.18.0-0ubuntu1.3