CVE-2019-20372: Medium severity Apple Xcode vulnerability
IDE Xcode Server. Multiple issues were addressed by updating nginx to version 1.21.0.
Other sources
NGINX before 1.17.7, with certain errorpage configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.
Credit
Affected Software
Remediation
Patch Available
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2019-20372?
The severity of CVE-2019-20372 is medium with a severity value of 5.3.
How does NGINX before 1.17.7 allow HTTP request smuggling?
NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling.
What is the affected software for CVE-2019-20372?
The affected software for CVE-2019-20372 includes NGINX versions before 1.17.7 and certain versions of Apple Xcode.
What is the remedy for CVE-2019-20372?
The remedy for CVE-2019-20372 is to update NGINX to version 1.17.7 or later.
Where can I find more information about CVE-2019-20372?
You can find more information about CVE-2019-20372 on the CVE website, NIST NVD, Red Hat Bugzilla, and Red Hat Security Advisory.