REDHAT-BUG-2450791: High severity Nginx NGINX Plus vulnerability
When the ngxmailauthhttpmodule module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server permits retry by returning the Auth-Wait response header. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2450791?
The severity of REDHAT-BUG-2450791 is considered high due to the potential for worker processes of NGINX to terminate unexpectedly.
How do I fix REDHAT-BUG-2450791?
To fix REDHAT-BUG-2450791, disable the ngx_mail_auth_http_module or update to the latest patched version of NGINX Plus or NGINX Open Source.
What causes the termination of worker processes as described in REDHAT-BUG-2450791?
The termination of worker processes in REDHAT-BUG-2450791 is triggered by undisclosed requests when CRAM-MD5 or APOP authentication is enabled.
Which versions of NGINX are affected by REDHAT-BUG-2450791?
Both NGINX Plus and NGINX Open Source are affected by REDHAT-BUG-2450791 when the ngx_mail_auth_http_module is enabled.
What should I do if my application is impacted by REDHAT-BUG-2450791?
If your application is impacted by REDHAT-BUG-2450791, you should assess your use of CRAM-MD5 or APOP authentication and apply necessary mitigations or patches.