Записи openresty
8 опубликованных записей вендора openresty.
Профиль для исследователя
- Попали в KEV
- 1 · 12,5 %
- С эксплойтом
- 1 · 12,5 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 75 %
- Медиана: публикация → KEV
- 0 дн.
Повторяющиеся классы
- CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')2
- CWE-193 Off-by-one Error1
- CWE-400 Uncontrolled Resource Consumption1
- CWE-407 Inefficient Algorithmic Complexity1
- CWE-787 Out-of-bounds Write1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
8 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
90Срочно | CVE-2023-44487Готовый эксплойт | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | Высокая7,5 | KEV | 100,0 % | 10 окт. 2023 г. |
46В плане | CVE-2021-23017Proof of concept | A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cauf5 · nginx · CWE-193 | Высокая7,7 | — | 53,5 % | 1 июн. 2021 г. |
43В плане | CVE-2018-9230Эксплойта нет | In OpenResty through 1.13.6.1, URI parameters are obtained using the ngx.req.get_uri_args and ngx.req.get_post_args functions that ignore paopenresty · openresty · CWE-89 | Критическая9,8 | — | 13,2 % | 2 апр. 2018 г. |
31Наблюдать | CVE-2020-11724Эксплойта нет | An issue was discovered in OpenResty before 1.15.8.4.openresty · openresty · CWE-444 | Высокая7,5 | — | 2,6 % | 12 апр. 2020 г. |
30Наблюдать | CVE-2024-33452Эксплойта нет | An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD reopenresty · lua-nginx-module · CWE-444 | Высокая7,7 | — | 0,8 % | 22 апр. 2025 г. |
30Наблюдать | CVE-2026-55233Эксплойта нет | OpenResty: Buffer overflow when writing PROXY protocol v2 header to upstreamopenresty · openresty · CWE-787 | Высокая7,5 | — | 0,5 % | 10 июл. 2026 г. |
23Наблюдать | CVE-2024-39702Эксплойта нет | In lj_str_hash.c in OpenResty 1.19.3.1 through 1.25.3.1, the string hashing function (used during string interning) allows HashDoS (Hash Denopenresty · openresty · CWE-407 | Средняя5,9 | — | 0,6 % | 23 июл. 2024 г. |
21Наблюдать | CVE-2020-36309Эксплойта нет | ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows unsafe characters in an argument when using the API to mutate openresty · lua-nginx-module | Средняя5,3 | — | 1,4 % | 6 апр. 2021 г. |
- CVE-2023-4448790Срочно
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware10 окт. 2023 г.
- CVE-2021-2301746В плане
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cau
ВысокаяCVSS 7,7Proof of conceptEPSS 53 %f5 · nginx1 июн. 2021 г.
- CVE-2018-923043В плане
In OpenResty through 1.13.6.1, URI parameters are obtained using the ngx.req.get_uri_args and ngx.req.get_post_args functions that ignore pa
КритическаяCVSS 9,8Эксплойта нетEPSS 13 %openresty · openresty2 апр. 2018 г.
- CVE-2020-1172431Наблюдать
An issue was discovered in OpenResty before 1.15.8.4.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %openresty · openresty12 апр. 2020 г.
- CVE-2024-3345230Наблюдать
An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD re
ВысокаяCVSS 7,7Эксплойта нетEPSS 1 %openresty · lua-nginx-module22 апр. 2025 г.
- CVE-2026-5523330Наблюдать
OpenResty: Buffer overflow when writing PROXY protocol v2 header to upstream
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %openresty · openresty10 июл. 2026 г.
- CVE-2024-3970223Наблюдать
In lj_str_hash.c in OpenResty 1.19.3.1 through 1.25.3.1, the string hashing function (used during string interning) allows HashDoS (Hash Den
СредняяCVSS 5,9Эксплойта нетEPSS 1 %openresty · openresty23 июл. 2024 г.
- CVE-2020-3630921Наблюдать
ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows unsafe characters in an argument when using the API to mutate
СредняяCVSS 5,3Эксплойта нетEPSS 1 %openresty · lua-nginx-module6 апр. 2021 г.