openresty kayıtları
openresty üreticisine ait 8 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %12,5
- Silahlaştırılmış
- 1 · %12,5
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %75
- Yayından KEV’e ortanca
- 0 gün
Tekrar eden sınıflar
- CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')2
- CWE-193 Off-by-one Error1
- CWE-400 Uncontrolled Resource Consumption1
- CWE-407 Inefficient Algorithmic Complexity1
- CWE-787 Out-of-bounds Write1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
8 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
90Hemen | CVE-2023-44487Silahlaştırılmış | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | Yüksek7,5 | KEV | %100,0 | 10 Eki 2023 |
46Planlayın | CVE-2021-23017Kavram kanıtı | A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cauf5 · nginx · CWE-193 | Yüksek7,7 | — | %53,5 | 1 Haz 2021 |
43Planlayın | CVE-2018-9230İstismar yok | In OpenResty through 1.13.6.1, URI parameters are obtained using the ngx.req.get_uri_args and ngx.req.get_post_args functions that ignore paopenresty · openresty · CWE-89 | Kritik9,8 | — | %13,2 | 2 Nis 2018 |
31İzleyin | CVE-2020-11724İstismar yok | An issue was discovered in OpenResty before 1.15.8.4.openresty · openresty · CWE-444 | Yüksek7,5 | — | %2,6 | 12 Nis 2020 |
30İzleyin | CVE-2024-33452İstismar yok | An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD reopenresty · lua-nginx-module · CWE-444 | Yüksek7,7 | — | %0,8 | 22 Nis 2025 |
30İzleyin | CVE-2026-55233İstismar yok | OpenResty: Buffer overflow when writing PROXY protocol v2 header to upstreamopenresty · openresty · CWE-787 | Yüksek7,5 | — | %0,5 | 10 Tem 2026 |
23İzleyin | CVE-2024-39702İstismar yok | In lj_str_hash.c in OpenResty 1.19.3.1 through 1.25.3.1, the string hashing function (used during string interning) allows HashDoS (Hash Denopenresty · openresty · CWE-407 | Orta5,9 | — | %0,6 | 23 Tem 2024 |
21İzleyin | CVE-2020-36309İstismar yok | ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows unsafe characters in an argument when using the API to mutate openresty · lua-nginx-module | Orta5,3 | — | %1,4 | 6 Nis 2021 |
- CVE-2023-4448790Hemen
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware10 Eki 2023
- CVE-2021-2301746Planlayın
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cau
YüksekCVSS 7,7Kavram kanıtıEPSS %53f5 · nginx1 Haz 2021
- CVE-2018-923043Planlayın
In OpenResty through 1.13.6.1, URI parameters are obtained using the ngx.req.get_uri_args and ngx.req.get_post_args functions that ignore pa
KritikCVSS 9,8İstismar yokEPSS %13openresty · openresty2 Nis 2018
- CVE-2020-1172431İzleyin
An issue was discovered in OpenResty before 1.15.8.4.
YüksekCVSS 7,5İstismar yokEPSS %3openresty · openresty12 Nis 2020
- CVE-2024-3345230İzleyin
An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD re
YüksekCVSS 7,7İstismar yokEPSS %1openresty · lua-nginx-module22 Nis 2025
- CVE-2026-5523330İzleyin
OpenResty: Buffer overflow when writing PROXY protocol v2 header to upstream
YüksekCVSS 7,5İstismar yokEPSS %0openresty · openresty10 Tem 2026
- CVE-2024-3970223İzleyin
In lj_str_hash.c in OpenResty 1.19.3.1 through 1.25.3.1, the string hashing function (used during string interning) allows HashDoS (Hash Den
OrtaCVSS 5,9İstismar yokEPSS %1openresty · openresty23 Tem 2024
- CVE-2020-3630921İzleyin
ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows unsafe characters in an argument when using the API to mutate
OrtaCVSS 5,3İstismar yokEPSS %1openresty · lua-nginx-module6 Nis 2021