HomeFreeBSD

Add patch for CVE-2019-20372

Description

Add patch for CVE-2019-20372

NGINX before 1.17.7, with certain error_page configurations,
allows HTTP request smuggling, as demonstrated by the ability
of an attacker to read unauthorized web pages in environments
where NGINX is being fronted by a load balancer.

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20372

PR: 243952
Reported by: koobs and many more
MFH: 2020Q1
Security: c1202de8-4b29-11ea-9673-4c72b94353b5
Sponsored by: Netzkommune GmbH

Details

Provenance
joneumAuthored on
Parents
rP525646: Add entry for nginx
Branches
Unknown
Tags
Unknown