F5-K000138445: High severity nginx vulnerability
Published Feb 14, 2024
·Updated
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate.
Affected Software
2 affected componentsFixes available
F5 NGINX Plus=31, =30
31
F5 NGINX Open Source>=1.25.0<=1.25.3
1.25.4
Event History
Feb 14, 2024
Advisory Published
via F5·01:35 PM
Frequently Asked Questions
1
What is the severity of F5-K000138445?
The severity of F5-K000138445 is considered critical due to potential service disruption.
2
How do I fix F5-K000138445?
To fix F5-K000138445, you should upgrade to NGINX Plus version 31 or 30, or NGINX Open Source version 1.25.4.
3
What systems are affected by F5-K000138445?
F5-K000138445 affects NGINX Plus versions 30 and 31 as well as NGINX Open Source versions 1.25.0 to 1.25.3.
4
What causes the issue in F5-K000138445?
F5-K000138445 is caused by undisclosed requests that lead to the termination of NGINX worker processes when using the HTTP/3 QUIC module.
5
Is there a workaround for F5-K000138445?
Currently, there are no recommended workarounds for F5-K000138445, and upgrading is the advised action.