Back to Database
Status published
Medium
CVE-2011-4968
nginx http proxy module does not verify peer identity of...
Vulnerability Description
nginx http proxy module does not verify peer identity of https origin server which could facilitate man-in-the-middle attack (MITM)
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2011-4968
Credits & Attribution
No credits recorded in the NVD database.
References
- https://security-tracker.debian.org/tracker/CVE-2011-4968
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-4968
- https://bugzilla.suse.com/show_bug.cgi?id=CVE-2011-4968
- https://access.redhat.com/security/cve/cve-2011-4968
- http://www.openwall.com/lists/oss-security/2013/01/03/8
- http://www.securityfocus.com/bid/57139
- https://exchange.xforce.ibmcloud.com/vulnerabilities/80952
More from nginx
View All →CVE-2022-35173
An issue was discovered in Nginx NJS v0.7.5. The JUMP...
High
7.5
CVE-2022-30503
Nginx NJS v0.7.2 was discovered to contain a segmentation violation...
Medium
5.5
CVE-2022-29780
Nginx NJS v0.7.2 was discovered to contain a segmentation violation...
Medium
5.5
CVE-2022-29779
Nginx NJS v0.7.2 was discovered to contain a segmentation violation...
Medium
5.5
CVE-2021-46461
njs through 0.7.0, used in NGINX, was discovered to contain...
Critical
9.8
Affected Vendor
nginx
View all reports →Affected Software
nginx
Vulnerable Versions:
through 1.6.2
Timeline
Official Publish:
November 19th, 2019
Last Modified:
August 7th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.