CVE-2011-4968

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
19/11/2019
Last modified:
21/11/2024

Description

nginx http proxy module does not verify peer identity of https origin server which could facilitate man-in-the-middle attack (MITM)

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:f5:nginx:0.7.61:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.62:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.64:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.65:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.7.66:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.33:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.35:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.36:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:0.8.40:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:1.2.6:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*