CVE-2013-4547
nginx - restriction bypass
EPSS 67.7%
描述
nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescaped space character in a URI.
如何修補 CVE-2013-4547
要修補 CVE-2013-4547,請將受影響套件升級到下列已修補版本。
- Debian/nginx—升級至 1.4.4-1 或更新版本
- Debian/nginx—升級至 1.2.1-2.2+wheezy2 或更新版本
CVE-2013-4547 正在被利用嗎?
可能 — EPSS 為 67.7%,屬於高被利用機率區間,建議優先修補。
受影響套件(2)
- from 0, < 1.4.4-1
- from 0, < 1.2.1-2.2+wheezy2