Description
nginx http proxy module does not verify peer identity of https origin server which could facilitate man-in-the-middle attack (MITM)
Remediation
References
Related Vulnerabilities
Moodle Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2018-14630)
WordPress Plugin Facebook Like Box Unspecified Vulnerability (1.0.17)
Oracle Application Server Other Vulnerability (CVE-2004-1369)
WordPress Plugin Great Quotes Cross-Site Scripting (1.0.0)
Jboss EAP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-0059)