nginx http proxy module does not verify peer identity of …
nginx http proxy module does not verify peer identity of https origin server which could facilitate man-in-the-middle attack (MITM)
References
- https://security-tracker.debian.org/tracker/CVE-2011-4968 x_refsource_MISC
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-4968 x_refsource_MISC
- https://bugzilla.suse.com/show_bug.cgi?id=CVE-2011-4968 x_refsource_MISC
- https://access.redhat.com/security/cve/cve-2011-4968 x_refsource_MISC
- http://www.openwall.com/lists/oss-security/2013/01/03/8 x_refsource_MISC
- http://www.securityfocus.com/bid/57139 x_refsource_MISC
- https://exchange.xforce.ibmcloud.com/vulnerabilities/80952 x_refsource_MISC
- https://security-tracker.debian.org/tracker/CVE-2011-4968 x_refsource_MISC x_transferred
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-4968 x_refsource_MISC x_transferred
- https://bugzilla.suse.com/show_bug.cgi?id=CVE-2011-4968 x_refsource_MISC x_transferred
- https://access.redhat.com/security/cve/cve-2011-4968 x_refsource_MISC x_transferred
- http://www.openwall.com/lists/oss-security/2013/01/03/8 x_refsource_MISC x_transferred
- http://www.securityfocus.com/bid/57139 x_refsource_MISC x_transferred
- https://exchange.xforce.ibmcloud.com/vulnerabilities/80952 x_refsource_MISC x_transferred
- https://security-tracker.debian.org/tracker/CVE-2011-4968 x_refsource_MISC
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-4968 x_refsource_MISC
- https://bugzilla.suse.com/show_bug.cgi?id=CVE-2011-4968 x_refsource_MISC
- https://access.redhat.com/security/cve/cve-2011-4968 x_refsource_MISC
- http://www.openwall.com/lists/oss-security/2013/01/03/8 x_refsource_MISC
- http://www.securityfocus.com/bid/57139 x_refsource_MISC
- https://exchange.xforce.ibmcloud.com/vulnerabilities/80952 x_refsource_MISC
- https://security-tracker.debian.org/tracker/CVE-2011-4968 x_refsource_MISC x_transferred
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-4968 x_refsource_MISC x_transferred
- https://bugzilla.suse.com/show_bug.cgi?id=CVE-2011-4968 x_refsource_MISC x_transferred
- https://access.redhat.com/security/cve/cve-2011-4968 x_refsource_MISC x_transferred
- http://www.openwall.com/lists/oss-security/2013/01/03/8 x_refsource_MISC x_transferred
- http://www.securityfocus.com/bid/57139 x_refsource_MISC x_transferred
- https://exchange.xforce.ibmcloud.com/vulnerabilities/80952 x_refsource_MISC x_transferred
Affected products
- ==through 1.6.2
Matching in nixpkgs
pkgs.nginx
Reverse proxy and lightweight webserver
pkgs.coc-nginx
nginx-language-server extension for coc.nvim
pkgs.nginx-doc
Reverse proxy and lightweight webserver (documentation)
-
nixos-unstable 2022-05-05
- nixpkgs-unstable 2022-05-05
- nixos-unstable-small 2022-05-05
-
nixos-25.11 2022-05-05
- nixos-25.11-small 2022-05-05
- nixpkgs-25.11-darwin 2022-05-05
pkgs.nginx-sso
SSO authentication provider for the auth_request nginx module
pkgs.nginxQuic
Reverse proxy and lightweight webserver
pkgs.nginxStable
Reverse proxy and lightweight webserver
pkgs.nginxMainline
Reverse proxy and lightweight webserver
pkgs.nginxShibboleth
Reverse proxy and lightweight webserver
pkgs.tailscale-nginx-auth
Tool that allows users to use Tailscale Whois authentication with NGINX as a reverse proxy
pkgs.vimPlugins.coc-nginx
nginx-language-server extension for coc.nvim
pkgs.nginx-language-server
Language server for nginx.conf
pkgs.nginx-config-formatter
nginx config file formatter
pkgs.prometheus-nginx-exporter
NGINX Prometheus Exporter for NGINX and NGINX Plus
pkgs.azure-cli-extensions.nginx
Microsoft Azure Command-Line Tools Nginx Extension
pkgs.prometheus-nginxlog-exporter
Export metrics from Nginx access log files to Prometheus
pkgs.python312Packages.certbot-nginx
Nginx plugin for Certbot
pkgs.python313Packages.certbot-nginx
Nginx plugin for Certbot
pkgs.python314Packages.certbot-nginx
Nginx plugin for Certbot
pkgs.nodePackages.%40yaegassy%2Fcoc-nginx
nginx-language-server extension for coc.nvim
pkgs.nodePackages_latest.%40yaegassy%2Fcoc-nginx
nginx-language-server extension for coc.nvim
pkgs.vimPlugins.nvim-treesitter-parsers.nginx
None
-
nixos-unstable 0.0.0+rev=47ade64
- nixpkgs-unstable 0.0.0+rev=47ade64
- nixos-unstable-small 0.0.0+rev=47ade64
Package maintainers
-
@ulrikstrid Ulrik Strid <ulrik.strid@outlook.com>
-
@katexochen Paul Meyer <katexochen0@gmail.com>
-
@fpletz Franz Pletz <fpletz@fnordicwalking.de>
-
@RaitoBezarius Ryan Lahfa <ryan@lahfa.xyz>
-
@helsinki-Jo Joachim Ernst <joachim.ernst@helsinki-systems.de>
-
@Conni2461 Simon Hauser <simon-hauser@outlook.com>
-
@dasJ Janne Heß <janne@hess.ooo>
-
@Baughn Svein Ove Aas <sveina@gmail.com>
-
@KAction Dmitry Bogatov <KAction@disroot.org>
-
@GaetanLepage Gaetan Lepage <gaetan@glepage.com>
-
@ambroisie Bruno BELANYI <bruno.nixpkgs@belanyi.fr>
-
@WilliButz Willi Butz <willibutz@posteo.de>
-
@globin Robin Gloster <mail@glob.in>
-
@benley Benjamin Staffin <benley@gmail.com>
-
@mmahut Marek Mahut <marek.mahut@gmail.com>
-
@phaer Paul Haerle <nix@phaer.org>