A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Impact: This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
1.18.0-6ubuntu111.18.0-6ubuntu121.18.0-6ubuntu141.18.0-6ubuntu14.11.18.0-6ubuntu14.101.18.0-6ubuntu14.111.18.0-6ubuntu14.121.18.0-6ubuntu14.131.18.0-6ubuntu14.141.18.0-6ubuntu14.15+12 more1.24.0-1ubuntu11.24.0-2ubuntu11.24.0-2ubuntu21.24.0-2ubuntu31.24.0-2ubuntu41.24.0-2ubuntu61.24.0-2ubuntu71.24.0-2ubuntu7.11.24.0-2ubuntu7.101.24.0-2ubuntu7.11+13 more1.28.0-6ubuntu11.28.1-2ubuntu11.28.1-3ubuntu11.28.2-2ubuntu11.28.3-2ubuntu11.28.3-2ubuntu1.11.28.3-2ubuntu1.101.28.3-2ubuntu1.21.28.3-2ubuntu1.31.28.3-2ubuntu1.4+5 moreExploitability
AV:NAC:HAT:NPR:NUI:NVulnerable System
VC:HVI:HVA:HSubsequent System
SC:NSI:NSA:NCVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N