REDHAT-BUG-2436738: Medium severity Nginx NGINX OSS vulnerability
A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers. An attacker with a man-in-the-middle (MITM) position on the upstream server side—along with conditions beyond the attacker's control—may be able to inject plain text data into the response from an upstream proxied server. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2436738?
The severity of REDHAT-BUG-2436738 is classified as high due to the potential for man-in-the-middle attacks.
How do I fix REDHAT-BUG-2436738?
To fix REDHAT-BUG-2436738, update NGINX OSS or NGINX Plus to the latest patched version available.
What types of servers are affected by REDHAT-BUG-2436738?
REDHAT-BUG-2436738 affects NGINX OSS and NGINX Plus when they are configured to proxy to upstream TLS servers.
What kind of attack is associated with REDHAT-BUG-2436738?
REDHAT-BUG-2436738 is associated with man-in-the-middle (MITM) attacks that allow attackers to inject plain text data.
Who reported REDHAT-BUG-2436738?
REDHAT-BUG-2436738 was reported by Red Hat through their bug tracking system.