CanSSOC advisory: Vulnerability – F5 patches critical flaw in NGINX
We received this report from CanSSOC about a critical vulnerability in NGINX. It is primarily a denial-of-service vulnerability, but F5 says it could also be used for Remote code execution. Only a private exploit exists at this point, but the researcher has said it will be withheld until users have sufficient time to apply patches, citing concerns over rapid exploitation. At present, the date for this is August 5th.
There is a mitigation listed below, and for a server to be exploitable, it must be running an impacted version and be using unnamed captures in map directives. Please either implement the mitigation or patch as soon as reasonable, but no later than August 5th.
Read more here: Source link
