ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows unsafe characters in an argument when using the API to mutate a URI, or a request or response header.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Lua-nginx-module | Openresty | * | 0.10.16 (excluding) |
Nginx | Ubuntu | bionic | * |
Nginx | Ubuntu | esm-infra-legacy/trusty | * |
Nginx | Ubuntu | esm-infra/xenial | * |
Nginx | Ubuntu | focal | * |
Nginx | Ubuntu | groovy | * |
Nginx | Ubuntu | trusty | * |
Nginx | Ubuntu | trusty/esm | * |
Nginx | Ubuntu | xenial | * |