CVE-2020-21699: Integer Overflow
Published Aug 22, 2023
·Updated
The web server Tengine 2.2.2 developed in the Nginx version from 0.5.6 thru 1.13.2 is vulnerable to an integer overflow vulnerability in the nginx range filter module, resulting in the leakage of potentially sensitive information triggered by specially crafted requests.
Affected Software
1 affected component
Alibaba Tengine Nginx=2.2.2
Event History
Aug 22, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this Tengine web server vulnerability?
The vulnerability ID is CVE-2020-21699.
2
What is the severity of CVE-2020-21699?
The severity of CVE-2020-21699 is high with a CVSS score of 7.5.
3
What is the affected software of CVE-2020-21699?
The affected software is the web server Tengine version 2.2.2.
4
How does CVE-2020-21699 vulnerability occur?
CVE-2020-21699 vulnerability occurs due to an integer overflow vulnerability in the nginx range filter module.
5
What is the potential impact of CVE-2020-21699?
CVE-2020-21699 can lead to the leakage of potentially sensitive information triggered by specially crafted requests.