BSA-2020-1130
21586
10 May 2021
10 May 2021
Closed
Medium
5.3
N/A
CVE-2019-20372
Summary Security Advisory ID : BSA-2020-1130 Component : NGINX Revision : 1.0
NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.
Affected Products
Brocade SANnav versions before SANnav 2.1.1
Products Confirmed Not Vulnerable
No other Brocade Fibre Channel Products from Broadcom products are currently known to be affected by this vulnerability.
Solution
A security update has been provided in Brocade SANnav 2.1.1 and higher releases.
Credit
This issue was discovered through security testing.
Revision History
| Version | Change | Date |
|---|---|---|
| 1.0 | Initial Publication | May 10, 2021 |