Out-of-bounds write in NGINX Plus and NGINX Open Source - CVE-2024-32760
Published: June 4, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error when processing HTTP/3 requests within the HTTP/3 QUIC module (ngx_http_v3_module). A remote attacker can send specially crafted HTTP/3 requests to the web server, trigger an out-of-bounds write and perform a denial of service (DoS) attack.
Affected software
NGINX Open Source
Oracle Communications Operations Monitor
Sensor Proxy
IBM Watson Discovery for IBM Cloud Pak for Data
How to mitigate CVE-2024-32760
NGINX Open Source - update to 1.26.1
Sensor Proxy - update to 1.4.0
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.6, 5.0.1