Description
NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.
Remediation
References
Related Vulnerabilities
Oracle JRE CVE-2017-10357 Vulnerability (CVE-2017-10357)
MediaWiki Improper Input Validation Vulnerability (CVE-2011-1579)
Oracle Database Server CVE-2011-0787 Vulnerability (CVE-2011-0787)
Oracle Database Server CVE-2018-2875 Vulnerability (CVE-2018-2875)
WordPress Plugin Rich Table of Contents Cross-Site Scripting (1.3.7)