CVE-2019-20372
MEDIUM 5.3EPSS 15.0%
NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.
- CVSS v3.1
- 5.3 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N - CVSS v2.0
- 4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N - EPSS
- 14.96% chance of exploitation in the next 30 days, 96th percentile
- Published
- 2020-01-09
- Updated
- 2024-08-05
Proof-of-concept exploits (3)
- 0xleft/CVE-2019-203726★ · 2023-09-16
- moften/CVE-2019-203721★ · 2025-05-06
- vuongnv3389-sec/CVE-2019-203720★ · 2022-04-06