Use-after-free in NGINX Plus and NGINX Open Source - CVE-2024-34161

 

Use-after-free in NGINX Plus and NGINX Open Source - CVE-2024-34161

Published: June 4, 2024


Vulnerability identifier: #VU90994
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-34161
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to a use-after-free error within the HTTP/3 QUIC module (ngx_http_v3_module). A remote attacker can send specially crafted HTTP/3 requests to the web server and read parts of free memory.


Affected software

NGINX Plus
NGINX Open Source
Sensor Proxy
IBM Watson Discovery for IBM Cloud Pak for Data

How to mitigate CVE-2024-34161

Install updates from vendor's website.

NGINX Plus - addressed in versions R31 P2, R32
NGINX Open Source - update to 1.26.1
Sensor Proxy - update to 1.4.0
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.6, 5.0.1

External References

Related Security Bulletins