RHSA-2020:5495: Moderate: nginx:1.16 security update
nginx is a web and proxy server supporting HTTP and other protocols, with a focus on high concurrency, performance, and low memory usage. Security Fix(es): nginx: HTTP request smuggling in configurations with URL redirect used as errorpage (CVE-2019-20372) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/nginxto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.3.0+8844+e5e7039f.1 - Upgrade
Upgrade
redhat/nginx-all-modulesto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.3.0+8844+e5e7039f.1 - Upgrade
Upgrade
redhat/nginx-filesystemto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.3.0+8844+e5e7039f.1 - Upgrade
Upgrade
redhat/nginx-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.3.0+8844+e5e7039f.1 - Upgrade
Upgrade
redhat/nginx-debugsourceto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.3.0+8844+e5e7039f.1 - Upgrade
Upgrade
redhat/nginx-mod-http-image-filterto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.3.0+8844+e5e7039f.1 - Upgrade
Upgrade
redhat/nginx-mod-http-image-filter-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.3.0+8844+e5e7039f.1 - Upgrade
Upgrade
redhat/nginx-mod-http-perlto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.3.0+8844+e5e7039f.1 - Upgrade
Upgrade
redhat/nginx-mod-http-perl-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.3.0+8844+e5e7039f.1 - Upgrade
Upgrade
redhat/nginx-mod-http-xslt-filterto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.3.0+8844+e5e7039f.1 - Upgrade
Upgrade
redhat/nginx-mod-http-xslt-filter-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.3.0+8844+e5e7039f.1 - Upgrade
Upgrade
redhat/nginx-mod-mailto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.3.0+8844+e5e7039f.1 - Upgrade
Upgrade
redhat/nginx-mod-mail-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.3.0+8844+e5e7039f.1 - Upgrade
Upgrade
redhat/nginx-mod-streamto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.3.0+8844+e5e7039f.1 - Upgrade
Upgrade
redhat/nginx-mod-stream-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.3.0+8844+e5e7039f.1 - Upgrade
Upgrade
redhat/nginxto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.3.0+8844+e5e7039f.1.aa - Upgrade
Upgrade
redhat/nginx-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.3.0+8844+e5e7039f.1.aa - Upgrade
Upgrade
redhat/nginx-debugsourceto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.3.0+8844+e5e7039f.1.aa - Upgrade
Upgrade
redhat/nginx-mod-http-image-filterto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.3.0+8844+e5e7039f.1.aa - Upgrade
Upgrade
redhat/nginx-mod-http-image-filter-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.3.0+8844+e5e7039f.1.aa - Upgrade
Upgrade
redhat/nginx-mod-http-perlto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.3.0+8844+e5e7039f.1.aa - Upgrade
Upgrade
redhat/nginx-mod-http-perl-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.3.0+8844+e5e7039f.1.aa - Upgrade
Upgrade
redhat/nginx-mod-http-xslt-filterto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.3.0+8844+e5e7039f.1.aa - Upgrade
Upgrade
redhat/nginx-mod-http-xslt-filter-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.3.0+8844+e5e7039f.1.aa - Upgrade
Upgrade
redhat/nginx-mod-mailto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.3.0+8844+e5e7039f.1.aa - Upgrade
Upgrade
redhat/nginx-mod-mail-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.3.0+8844+e5e7039f.1.aa - Upgrade
Upgrade
redhat/nginx-mod-streamto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.3.0+8844+e5e7039f.1.aa - Upgrade
Upgrade
redhat/nginx-mod-stream-debuginfoto a version that resolves this vulnerability.Fixed in 1.16.1-1.module+el8.3.0+8844+e5e7039f.1.aa - Upgrade
Upgrade
nginxto a version that resolves this vulnerability.Fixed in 1.16Patch CVE-2019-20372
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:5495?
The vulnerability is classified with a moderate severity level.
How do I fix RHSA-2020:5495?
To fix RHSA-2020:5495, upgrade to the nginx version 1.16.1-1.module+el8.3.0+8844+e5e7039f.1 or later.
What vulnerabilities does RHSA-2020:5495 address?
RHSA-2020:5495 addresses an HTTP request smuggling vulnerability in nginx configurations using URL redirect as error_page, identified as CVE-2019-20372.
Which versions of nginx are affected by RHSA-2020:5495?
Versions of nginx prior to 1.16.1-1.module+el8.3.0+8844+e5e7039f.1 are affected by this vulnerability.
Is RHSA-2020:5495 applicable to all operating systems?
RHSA-2020:5495 specifically applies to Red Hat Enterprise Linux 8 systems using the nginx package.