Description
NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Custom Fields Search Cross-Site Scripting (0.3.28)
WordPress Plugin Analytics Stats Counter Statistics PHP Object Injection (1.2.2.5)
Apache Traffic Server Exposure of Resource to Wrong Sphere Vulnerability (CVE-2018-8040)
Joomla Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2015-5397)