Use-after-free in NGINX Plus and NGINX Open Source - CVE-2024-34161
Published: June 4, 2024
Vulnerability identifier: #VU90994
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-34161
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to a use-after-free error within the HTTP/3 QUIC module (ngx_http_v3_module). A remote attacker can send specially crafted HTTP/3 requests to the web server and read parts of free memory.
Affected software
NGINX Plus
NGINX Open Source
Sensor Proxy
IBM Watson Discovery for IBM Cloud Pak for Data
NGINX Open Source
Sensor Proxy
IBM Watson Discovery for IBM Cloud Pak for Data
How to mitigate CVE-2024-34161
Install updates from vendor's website.
NGINX Plus - addressed in versions R31 P2, R32
NGINX Open Source - update to 1.26.1
Sensor Proxy - update to 1.4.0
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.6, 5.0.1
NGINX Open Source - update to 1.26.1
Sensor Proxy - update to 1.4.0
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.6, 5.0.1