5.8
CVSSv2

CVE-2011-4968

Published: 19/11/2019 Updated: 10/11/2021
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 4.8 | Impact Score: 2.5 | Exploitability Score: 2.2
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

nginx http proxy module does not verify peer identity of https origin server which could facilitate man-in-the-middle attack (MITM)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

f5 nginx 0.7.61

f5 nginx 0.7.62

f5 nginx 0.7.64

f5 nginx 0.7.65

f5 nginx 0.7.66

f5 nginx 0.8.33

f5 nginx 0.8.35

f5 nginx 0.8.36

f5 nginx 0.8.40

f5 nginx 1.2.6

debian debian linux 8.0

Vendor Advisories

Debian Bug report logs - #697940 [CVE-2011-4968] nginx does not verify the backend's identity when proxying to an https origin server Package: nginx; Maintainer for nginx is Debian Nginx Maintainers <pkg-nginx-maintainers@alioth-listsdebiannet>; Source for nginx is src:nginx (PTS, buildd, popcon) Reported by: Daniel Kahn G ...