Integer Overflow Vulnerability in Tengine Web Server by Nginx
CVE-2020-21699

7.5HIGH

Key Information:

Vendor

Alibaba

Status
Vendor
CVE Published:
22 August 2023

What is CVE-2020-21699?

The Tengine web server version 2.2.2, derived from the Nginx web server, is susceptible to an integer overflow vulnerability within the nginx range filter module. This flaw can be exploited by sending specially crafted requests, leading to the potential exposure of sensitive information. The vulnerability affects Nginx versions ranging from 0.5.6 through 1.13.2, posing a risk to web applications relying on this server technology.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.