CVE-2024-10318
- EPSS 0.12%
- Published 06.11.2024 17:15:13
- Last modified 08.11.2024 19:51:49
A session fixation issue was discovered in the NGINX OpenID Connect reference implementation, where a nonce was not checked at login time. This flaw allows an attacker to fix a victim's session to an attacker-controlled account. As a result, although...
CVE-2023-44487
- EPSS 94.44%
- Published 10.10.2023 14:15:10
- Last modified 11.06.2025 17:29:54
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CVE-2022-41741
- EPSS 0.83%
- Published 19.10.2022 22:15:12
- Last modified 21.11.2024 07:23:46
NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local atta...
CVE-2022-41742
- EPSS 0.07%
- Published 19.10.2022 22:15:12
- Last modified 21.11.2024 07:23:46
NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local atta...
- EPSS 0.09%
- Published 19.10.2022 22:15:12
- Last modified 21.11.2024 07:23:46
NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_hls_module that might allow a local attacker to corrupt NGINX worker memory, resulting in its crash or potential other impact using a specially crafted audio or ...
CVE-2022-30535
- EPSS 0.54%
- Published 04.08.2022 18:15:09
- Last modified 21.11.2024 07:02:53
In versions 2.x before 2.3.0 and all versions of 1.x, An attacker authorized to create or update ingress objects can obtain the secrets available to the NGINX Ingress Controller. Note: Software versions which have reached End of Technical Support (Eo...
CVE-2021-23055
- EPSS 0.18%
- Published 21.04.2022 19:15:08
- Last modified 21.11.2024 05:51:13
On version 2.x before 2.0.3 and 1.x before 1.12.3, the command line restriction that controls snippet use with NGINX Ingress Controller does not apply to Ingress objects. Note: Software versions which have reached End of Technical Support (EoTS) are ...