NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
The vulnerability manifests when a rewrite directive is preceded by another rewrite, if, or set directive, and the PCRE regular expression contains an unnamed capture (e.g., $1, $2) in combination with a replacement string containing a question mark (?). An unauthenticated attacker can send crafted HTTP requests that trigger a heap buffer overflow in the NGINX worker process. Successful exploitation of the vulnerability requires certain conditions to be met that are partially independent of the attacker, which reflects a high level of attack complexity (AC:H in the CVSS vector).
In a typical attack scenario, an attacker can cause an NGINX worker process restart, resulting in temporary service unavailability. On systems with ASLR disabled or after bypassing it, remote code execution (RCE) is possible in the context of the NGINX worker process.
Patches available from the vendor should be applied in accordance with the references (F5 article K000161019: https://my.f5.com/manage/s/article/K000161019). As an additional remedial measure, it is recommended to ensure that the ASLR mechanism is enabled on servers hosting NGINX, which significantly complicates effective code execution by an attacker.
NGINX Plus and NGINX Open Source — specific versions indicated in the vendor references (F5 article K000161019). Versions that have reached end of technical support (EoTS) are not subject to this assessment.
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XF5 Dos
APPF54.8.04.3.0 – 4.7.0F5 nginx Gateway Fabric
APPF51.3.0 – 1.6.22.0.0 – 2.5.1F5 nginx Ingress Controller
APPF55.0.0 – 5.4.13.5.0 – 3.7.24.0.0 – 4.0.1F5 nginx Instance Manager
APPF52.16.0 – 2.21.1F5 nginx Open Source
APPF50.6.27 – 1.30.0F5 nginx Plus
APPF5r32 – r36F5 Waf
APPF54.9.0 – 4.16.05.1.0 – 5.8.05.9.0 – 5.12.1
Related vulnerabilities
Heap buffer overflow w NGINX Plus i NGINX Open Source — DoS i możliwy RCE
Use-after-Free w module HTTP/3 QUIC NGINX — możliwość RCE
NGINX Plus/Open Source: heap buffer overflow w modułach HTTP/2 i gRPC
Heap buffer overflow w NGINX w module ngx_http_rewrite_module (RCE)
F5 NGINX Ingress Controller – DoS poprzez NULL pointer dereference (CWE-476)