CVE.RADIO
FREN

CVE-2023-44487

nginxVulnerabilityPatched

No public exploitation has been reported so far. A fixed version is available (see the table below).

Recommended action: Update to the fixed version listed for your distribution using the native package manager.

Affected & fixed versions by distribution

Versions are the native distribution strings (backport-aware): RHEL/Debian/SUSE backport fixes, so compare with the distro version comparator (dpkg / rpm / vercmp), not the upstream version.

DistributionPackageAffectedFixed versionStatus
Debian:11nginx--affected (no fix yet)
Debian:12nginx--affected (no fix yet)
Debian:13nginx-1.24.0-2fixed
Debian:14nginx-1.24.0-2fixed
Debian:11varnish--affected (no fix yet)
Debian:12varnish--affected (no fix yet)
Debian:13varnish-7.5.0-1fixed
SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOSnginx-1.21.5-150400.3.6.1fixed
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSSnginx-1.21.5-150400.3.6.1fixed
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOSnginx-1.21.5-150400.3.6.1fixed
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSSnginx-1.21.5-150400.3.6.1fixed
SUSE:Linux Enterprise Server 15 SP4-LTSSnginx-1.21.5-150400.3.6.1fixed
SUSE:Linux Enterprise Server 15 SP5-LTSSnginx-1.21.5-150400.3.6.1fixed
SUSE:Linux Enterprise Server for SAP Applications 15 SP4nginx-1.21.5-150400.3.6.1fixed
SUSE:Linux Enterprise Server for SAP Applications 15 SP5nginx-1.21.5-150400.3.6.1fixed
SUSE:Manager Proxy 4.3nginx-1.21.5-150400.3.6.1fixed
SUSE:Manager Server 4.3nginx-1.21.5-150400.3.6.1fixed
SUSE:Linux Enterprise Module for Server Applications 15 SP6nginx-1.21.5-150600.10.3.1fixed
openSUSE:Leap 15.6nginx-1.21.5-150600.10.3.1fixed
openSUSE:Tumbleweedapache2-2.4.58-1.1fixed
openSUSE:Tumbleweedvarnish-7.4.2-1.1fixed
Red Hat:openshift:4.14::el9kernel-0:5.14.0-284.36.1.el9_2fixed
Red Hat:enterprise_linux:9::appstreamnginx-1:1.22.1-5.module+el9.3.0.z+20438+032561a0fixed
Red Hat:enterprise_linux:9::appstreamnginx-1:1.20.1-14.el9_2.1fixed
Red Hat:enterprise_linux:8::appstreamnginx-1:1.20.1-1.module+el8.8.0+20359+9bd89172.1fixed
Red Hat:enterprise_linux:8::appstreamnginx-1:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1fixed
Red Hat:rhel_eus:9.0::appstreamnginx-1:1.20.1-10.el9_0.1fixed
Red Hat:rhel_eus:8.6::appstreamnginx-1:1.20.1-1.module+el8.6.0+20350+58c16214.1fixed
Red Hat:enterprise_linux:9::appstreamnginx-1:1.22.1-3.module+el9.2.0.z+20353+5a828d50.1fixed
Red Hat:enterprise_linux:9::appstreamvarnish-0:6.6.2-3.el9_2.1fixed
Red Hat:rhel_eus:9.0::appstreamvarnish-0:6.6.2-2.el9_0.2fixed
Red Hat:enterprise_linux:8::appstreamvarnish-0:6.0.8-3.module+el8.8.0+20455+bdc2c048.1fixed
Red Hat:rhel_eus:8.6::appstreamvarnish-0:6.0.8-2.module+el8.6.0+20465+cbb0694f.2fixed
Red Hat:rhel_aus:8.4::appstreamvarnish-0:6.0.6-2.module+el8.4.0+20467+7fe641ed.4fixed
Red Hat:rhel_e4s:8.4::appstreamvarnish-0:6.0.6-2.module+el8.4.0+20467+7fe641ed.4fixed
Red Hat:rhel_tus:8.4::appstreamvarnish-0:6.0.6-2.module+el8.4.0+20467+7fe641ed.4fixed
Red Hat:rhel_aus:8.2::appstreamvarnish-0:6.0.2-2.module+el8.2.0+20470+5fdd0c40.3fixed
Red Hat:rhel_e4s:8.2::appstreamvarnish-0:6.0.2-2.module+el8.2.0+20470+5fdd0c40.3fixed
Red Hat:rhel_tus:8.2::appstreamvarnish-0:6.0.2-2.module+el8.2.0+20470+5fdd0c40.3fixed
Red Hat:rhel_e4s:8.1::appstreamvarnish-0:6.0.2-2.module+el8.1.0+20476+646a44ec.3fixed

Sources