NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when configured with the ssl_verify_client on and ssl_ocsp on directives, allowing the TLS handshake to succeed even after an OCSP check identifies the certificate as revoked.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:a:f5:nginx_plus:r33:*:*:*:*:*:*:*",
"cpe:2.3:a:f5:nginx_plus:r33:p1:*:*:*:*:*:*",
"cpe:2.3:a:f5:nginx_plus:r33:p2:*:*:*:*:*:*",
"cpe:2.3:a:f5:nginx_plus:r33:p3:*:*:*:*:*:*",
"cpe:2.3:a:f5:nginx_plus:r34:*:*:*:*:*:*:*",
"cpe:2.3:a:f5:nginx_plus:r34:p1:*:*:*:*:*:*",
"cpe:2.3:a:f5:nginx_plus:r34:p2:*:*:*:*:*:*",
"cpe:2.3:a:f5:nginx_plus:r35:p1:*:*:*:*:*:*",
"cpe:2.3:a:f5:nginx_plus:r36:*:*:*:*:*:*:*",
"cpe:2.3:a:f5:nginx_plus:r36:p1:*:*:*:*:*:*",
"cpe:2.3:a:f5:nginx_plus:r36:p2:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "r33"
},
{
"last_affected": "r33"
},
{
"introduced": "r33-p1"
},
{
"last_affected": "r33-p1"
},
{
"introduced": "r33-p2"
},
{
"last_affected": "r33-p2"
},
{
"introduced": "r33-p3"
},
{
"last_affected": "r33-p3"
},
{
"introduced": "r34"
},
{
"last_affected": "r34"
},
{
"introduced": "r34-p1"
},
{
"last_affected": "r34-p1"
},
{
"introduced": "r34-p2"
},
{
"last_affected": "r34-p2"
},
{
"introduced": "r35-p1"
},
{
"last_affected": "r35-p1"
},
{
"introduced": "r36"
},
{
"last_affected": "r36"
},
{
"introduced": "r36-p1"
},
{
"last_affected": "r36-p1"
},
{
"introduced": "r36-p2"
},
{
"last_affected": "r36-p2"
}
],
"source": "CPE_STRING",
"vendor_product": "f5:nginx_plus"
}
]
}{
"cpe": "cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0.5.13"
},
{
"last_affected": "0.9.7"
},
{
"introduced": "1.27.2"
},
{
"fixed": "1.28.3"
},
{
"introduced": "1.29.0"
},
{
"fixed": "1.29.7"
}
],
"source": "CPE_RANGE"
}