First published: Tue Aug 22 2023(Updated: )
The web server Tengine 2.2.2 developed in the Nginx version from 0.5.6 thru 1.13.2 is vulnerable to an integer overflow vulnerability in the nginx range filter module, resulting in the leakage of potentially sensitive information triggered by specially crafted requests.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Alibaba Tengine | =2.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-21699.
The severity of CVE-2020-21699 is high with a CVSS score of 7.5.
The affected software is the web server Tengine version 2.2.2.
CVE-2020-21699 vulnerability occurs due to an integer overflow vulnerability in the nginx range filter module.
CVE-2020-21699 can lead to the leakage of potentially sensitive information triggered by specially crafted requests.