CVE-2014-3616

CVSS v2.0 4.3 (Medium)
43% Progress
EPSS 0.23 % (62th)
0.23% Progress
Affected Products 2
Advisories 9

nginx 0.5.6 through 1.7.4, when using the same shared ssl_session_cache or ssl_session_ticket_key for multiple servers, can reuse a cached SSL session for an unrelated context, which allows remote attackers with certain privileges to conduct "virtual host confusion" attacks.

Weaknesses
CWE-613
Insufficient Session Expiration
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2014-12-08 11:59:03
(9 years ago)
Updated Date
2021-11-10 15:59:33
(2 years ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  F5 Nginx from 0.5.6 version and prior 1.6.2 version cpe:2.3:a:f5:nginx >= 0.5.6 < 1.6.2
  F5 Nginx from 1.7.0 version and prior 1.7.5 version cpe:2.3:a:f5:nginx >= 1.7.0 < 1.7.5

Configuration #2

    CPE23 From Up To
  Debian Linux 7.0 cpe:2.3:o:debian:debian_linux:7.0
  Debian Linux 8.0 cpe:2.3:o:debian:debian_linux:8.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...