
Vulnerability Impact This vulnerability affects all Nginx default configuration modules from version 0.5.6 to 1.13.2. An attacker only needs to enable caching to send malicious requests for remote attacks, causing information disclosure. When the Nginx server uses a proxy cache, the attacker can exploit this vulnerability to obtain the server's backend real IP or other sensitive information. Through our analysis, we determine that this vulnerability is easy to exploit and can be classified as a low-hanging-fruit vulnerability, which also has certain exploitation value in real network attacks.
Affected Versions Nginx version 0.5.6 - 1.13.2
Fixed Versions Nginx version 1.13.3, 1.12.1