VulnerabilityModified
CVE-2013-4547
nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescaped space character in a URI.
HIGH 7.5EPSS 67.7%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 67.7%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescaped space character in a URI.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 67.72% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-116
- Affected
- f5/nginx · suse/lifecycle management server · suse/studio onsite · suse/webyast · opensuse/opensuse
- Source
- secalert@redhat.com
References
- http://lists.opensuse.org/opensuse-security-announce/2013-12/msg00007.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-11/msg00084.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-11/msg00118.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-11/msg00119.htmlMailing List, Third Party Advisory
- http://mailman.nginx.org/pipermail/nginx-announce/2013/000125.htmlMitigation, Vendor Advisory
- http://secunia.com/advisories/55757Third Party Advisory
- http://secunia.com/advisories/55822Third Party Advisory
- http://secunia.com/advisories/55825Third Party Advisory
- http://www.debian.org/security/2012/dsa-2802Broken Link
- http://lists.opensuse.org/opensuse-security-announce/2013-12/msg00007.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-11/msg00084.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-11/msg00118.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-11/msg00119.htmlMailing List, Third Party Advisory
- http://mailman.nginx.org/pipermail/nginx-announce/2013/000125.htmlMitigation, Vendor Advisory
- http://secunia.com/advisories/55757Third Party Advisory
- http://secunia.com/advisories/55822Third Party Advisory
- http://secunia.com/advisories/55825Third Party Advisory
- http://www.debian.org/security/2012/dsa-2802Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.